CVE-2012-5660: Red Hat Automatic Bug Reporting Tool

Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.

abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes."

Affected products

  • Red Hat Automatic Bug Reporting Tool: up to and including 2.0.9; version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; …

Published 2013-03-12. Last modified 2026-06-16.