PT-2015-6834 · Red Hat+1 · Abrt+2

Rebel

·

Published

2015-11-23

·

Updated

2016-12-07

·

CVE-2015-5287

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ABRT versions prior to 2.7.1
Description The issue allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. This can be demonstrated by files such as /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
Recommendations For versions prior to 2.7.1, update to version 2.7.1 or later to resolve the issue.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2015_2505
CVE-2015-5287
RHSA-2015:2505
RHSA-2015_2505

Affected Products

Abrt
Centos
Red Hat