CVE-2015-1870: Red Hat Automatic Bug Reporting Tool

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages via unspecified vectors.

Affected products

  • Red Hat Automatic Bug Reporting Tool: up to and including 2.1.11

Published 2017-06-26. Last modified 2026-06-17.