CVE-2015-5287
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
Preallarme: sfruttamento osservato
- Sfruttamento osservato dal 20 ago 2026
- Non ancora nel catalogo ufficiale CISA
- Primo attacco osservato 3908 giorni dopo la divulgazione
Fonte: VulnCheck KEV · 20 ago 2026
Punteggio CVSS6.9 / 10
AV:L/AC:M/Au:N/C:C/I:C/A:CTipo di debolezza (CWE)CWE-59
Vendorredhat
Prodotti coinvolti
| Vendor | Prodotto | Versioni |
|---|---|---|
| redhat | automatic bug reporting tool | <= 2.7.0 |
| redhat | enterprise linux desktop | 7.0 |
| redhat | enterprise linux hpc node | 7.0 |
| redhat | enterprise linux server | 7.0 |
| redhat | enterprise linux workstation | 7.0 |
Articoli correlati
This product uses the NVD API but is not endorsed or certified by the NVD.
