CVE-2012-1106: Red Hat Automatic Bug Reporting Tool
Low severity, CVSS 1.9. EPSS: 0.4% chance of exploitation in the next 30 days.
The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.
Affected products
- Red Hat Automatic Bug Reporting Tool: up to and including 2.0.7
Published 2012-07-03. Last modified 2026-06-16.