CVE-2015-5287

MEDIUM6.9Publicada el 7 de diciembre de 2015

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.

Preaviso: explotación observada

  • Explotación observada desde el 20 ago 2026
  • Todavía no está en el catálogo oficial de CISA
  • Primer ataque observado 3908 días después de la divulgación

Fuente: VulnCheck KEV · 20 ago 2026

Puntuación CVSS6.9 / 10AV:L/AC:M/Au:N/C:C/I:C/A:C
Tipo de debilidad (CWE)CWE-59
Fabricantesredhat

Productos afectados

FabricantesProdottoVersioni
redhatautomatic bug reporting tool<= 2.7.0
redhatenterprise linux desktop7.0
redhatenterprise linux hpc node7.0
redhatenterprise linux server7.0
redhatenterprise linux workstation7.0

Artículos relacionados

This product uses the NVD API but is not endorsed or certified by the NVD.

Base de datos CVE