CVE-2012-1106

low
Published 2012-07-03 · Modified 2026-04-29
CVSS v3
CVSS v2
1.9
VIR risk
1.9

Description

The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://fedorahosted.org/abrt/changeset/23d6997d7886abe118c28254f7f73f0b19b2d4e0

Application impact

VendorProductVersionsFixed
redhat redhatautomatic_bug_reporting_tool{"endIncluding":"2.0.7"}

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.