CVE-2015-5287

MEDIUM6.9Pubblicata il 7 dicembre 2015

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.

Preallarme: sfruttamento osservato

  • Sfruttamento osservato dal 20 ago 2026
  • Non ancora nel catalogo ufficiale CISA
  • Primo attacco osservato 3908 giorni dopo la divulgazione

Fonte: VulnCheck KEV · 20 ago 2026

Punteggio CVSS6.9 / 10AV:L/AC:M/Au:N/C:C/I:C/A:C
Tipo di debolezza (CWE)CWE-59
Vendorredhat

Prodotti coinvolti

VendorProdottoVersioni
redhatautomatic bug reporting tool<= 2.7.0
redhatenterprise linux desktop7.0
redhatenterprise linux hpc node7.0
redhatenterprise linux server7.0
redhatenterprise linux workstation7.0

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

Database CVE