CVE-2015-5287
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
Alerte précoce : exploitation observée
- Exploitation observée depuis le 20 août 2026
- Pas encore dans le catalogue officiel de la CISA
- Première attaque observée 3908 jours après la divulgation
Source : VulnCheck KEV · 20 août 2026
Score CVSS6.9 / 10
AV:L/AC:M/Au:N/C:C/I:C/A:CType de faiblesse (CWE)CWE-59
Éditeursredhat
Produits concernés
| Éditeurs | Prodotto | Versioni |
|---|---|---|
| redhat | automatic bug reporting tool | <= 2.7.0 |
| redhat | enterprise linux desktop | 7.0 |
| redhat | enterprise linux hpc node | 7.0 |
| redhat | enterprise linux server | 7.0 |
| redhat | enterprise linux workstation | 7.0 |
Articles liés
This product uses the NVD API but is not endorsed or certified by the NVD.
