CVE-2015-5287
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
Frühwarnung: Ausnutzung beobachtet
- Ausnutzung beobachtet seit dem 20. Aug. 2026
- Noch nicht im offiziellen CISA-Katalog
- Erster Angriff 3908 Tage nach der Veröffentlichung beobachtet
Quelle: VulnCheck KEV · 20. Aug. 2026
CVSS-Score6.9 / 10
AV:L/AC:M/Au:N/C:C/I:C/A:CSchwachstellentyp (CWE)CWE-59
Herstellerredhat
Betroffene Produkte
| Hersteller | Prodotto | Versioni |
|---|---|---|
| redhat | automatic bug reporting tool | <= 2.7.0 |
| redhat | enterprise linux desktop | 7.0 |
| redhat | enterprise linux hpc node | 7.0 |
| redhat | enterprise linux server | 7.0 |
| redhat | enterprise linux workstation | 7.0 |
Verwandte Artikel
This product uses the NVD API but is not endorsed or certified by the NVD.
