PT-2026-49076 · Libreport+1 · Libreport+1
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
libreport (affected versions not specified)
Description
A content injection issue exists in the ABRT post-create event handler scripts within libreport. The event script retrieves log entries from the systemd journal for crashed processes and writes them to files in the dump directory. Because embedded control characters are not sanitized, a local user can inject arbitrary content into the journal output by including newline characters in syslog messages, allowing them to control the content written to dump directory files by the root user.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocky Linux
Libreport