Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2015-5287

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.05
EPSS Ranking 91.6%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.9
Proposed Action
Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Ransomware Campaign
Unknown
References
Products affected by CVE-2015-5287


Contact Us

Shodan ® - All rights reserved