CVE-2015-5287

MEDIUM6.9Published on December 7, 2015

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.

Early warning: exploitation observed

  • Exploitation observed since Aug 20, 2026
  • Not yet in the official CISA catalogue
  • First attack observed 3908 days after disclosure

Source: VulnCheck KEV · Aug 20, 2026

CVSS score6.9 / 10AV:L/AC:M/Au:N/C:C/I:C/A:C
Weakness type (CWE)CWE-59
Vendorsredhat

Affected products

VendorsProdottoVersioni
redhatautomatic bug reporting tool<= 2.7.0
redhatenterprise linux desktop7.0
redhatenterprise linux hpc node7.0
redhatenterprise linux server7.0
redhatenterprise linux workstation7.0

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database