CVE-2015-5287
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
Early warning: exploitation observed
- Exploitation observed since Aug 20, 2026
- Not yet in the official CISA catalogue
- First attack observed 3908 days after disclosure
Source: VulnCheck KEV · Aug 20, 2026
CVSS score6.9 / 10
AV:L/AC:M/Au:N/C:C/I:C/A:CWeakness type (CWE)CWE-59
Vendorsredhat
Affected products
| Vendors | Prodotto | Versioni |
|---|---|---|
| redhat | automatic bug reporting tool | <= 2.7.0 |
| redhat | enterprise linux desktop | 7.0 |
| redhat | enterprise linux hpc node | 7.0 |
| redhat | enterprise linux server | 7.0 |
| redhat | enterprise linux workstation | 7.0 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
