CVE-2015-3315
Find out more about CVE-2015-3315 from the MITRE CVE dictionary dictionary and NIST NVD.
Statement
This issue affects the versions of the abrt package as shipped with Red Hat Enterprise Linux 6 and 7.
CVSS v2 metrics
| Base Score | 7.2 |
|---|---|
| Base Metrics | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| Access Vector | Local |
| Access Complexity | Low |
| Authentication | None |
| Confidentiality Impact | Complete |
| Integrity Impact | Complete |
| Availability Impact | Complete |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Red Hat Security Errata
| Platform | Errata | Release Date |
|---|---|---|
| Red Hat Enterprise Linux 6 (abrt) | RHSA-2015:1210 | 2015-07-07 |
| Red Hat Enterprise Linux 7 (abrt) | RHSA-2015:1083 | 2015-06-09 |
Mitigation
It is recommended to disable abrt via the following command line, till the flaws have been resolved:
sysctl -w kern.core_pattern=core
Note: This will reset, if abrt is re-started.
