{"cves":["CVE-2015-5273","CVE-2015-5302","CVE-2015-5287"],"cvss":0.0,"database_specific":{"severity":"MODERATE"},"description":"abrt\n[2.1.11-35.0.1]\n- Drop libreport-rhel and libreport-plugin-rhtsupport requires\n\n[2.1.11-35]\n- make /var/spool/abrt owned by root\n- remove 'r' from /var/spool/abrt for other users\n- abrt-action-install-debug-info: use secure temporary directory\n- stop saving abrt's core files to /var/spool/abrt if DebugLevel  1\n- Fixes for: CVE-2015-5273 and CVE-2015-5287\n- Resolves: #1266853\n\nlibreport\n[2.1.11-31.0.1]\n- Update workflow xml for Oracle [18945470]\n- Add oracle-enterprise.patch and oracle-enterprise-po.patch\n- Remove libreport-plugin-rhtsupport and libreport-rhel\n- Added orabug20390725.patch to remove redhat reference [bug 20390725]\n- Added Bug20357383.patch to remove redhat reference [bug 20357383]\n\n[2.1.11-31]\n- save all files changed by the reporter in the reporting GUI\n- Fixes CVE-2015-5302\n- Related: #1266853","id":"ELSA-2015-2505","ovalId":"oval:com.oracle.elsa:def:20152505","source":"oracle_linux","title":"ELSA-2015-2505:  abrt and libreport security update (MODERATE)","url":"https://linux.oracle.com/errata/ELSA-2015-2505.html"}