CVE-2015-5287

MEDIUM6.9Veröffentlicht am 7. Dezember 2015

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.

Frühwarnung: Ausnutzung beobachtet

  • Ausnutzung beobachtet seit dem 20. Aug. 2026
  • Noch nicht im offiziellen CISA-Katalog
  • Erster Angriff 3908 Tage nach der Veröffentlichung beobachtet

Quelle: VulnCheck KEV · 20. Aug. 2026

CVSS-Score6.9 / 10AV:L/AC:M/Au:N/C:C/I:C/A:C
Schwachstellentyp (CWE)CWE-59
Herstellerredhat

Betroffene Produkte

HerstellerProdottoVersioni
redhatautomatic bug reporting tool<= 2.7.0
redhatenterprise linux desktop7.0
redhatenterprise linux hpc node7.0
redhatenterprise linux server7.0
redhatenterprise linux workstation7.0

Verwandte Artikel

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE-Datenbank