PT-2026-49075 · Libreport+1 · Libreport+1
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libreport (affected versions not specified)
Description
A symlink following issue exists in the ABRT post-create event handler scripts. These scripts write output files using shell redirections without the
O NOFOLLOW flag (a flag that prevents a file from being opened if it is a symbolic link). If a target file is replaced with a symlink, the shell process running with root privileges follows the link and writes content to the target, enabling arbitrary file overwrites on the system.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocky Linux
Libreport