The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle_linux | — | Upgrade abrt-guiUpgrade abrt-addon-vmcoreUpgrade abrt-addon-xorgUpgrade libreport-gtkUpgrade libreport-webUpgrade abrt-tuiUpgrade abrt-gui-develUpgrade abrt-console-notificationUpgrade abrt-addon-pstoreoopsUpgrade libreport-cliUpgrade abrt-pythonUpgrade abrt-python-docUpgrade libreport-gtk-develUpgrade abrt-libsUpgrade libreport-plugin-ureportUpgrade libreport-web-develUpgrade abrt-dbusUpgrade libreport-plugin-bugzillaUpgrade abrt-retrace-clientUpgrade libreport-plugin-kerneloopsUpgrade abrt-develUpgrade abrt-addon-upload-watchUpgrade libreport-plugin-mailxUpgrade abrtUpgrade libreport-pythonUpgrade libreportUpgrade libreport-rhel-bugzillaUpgrade abrt-addon-pythonUpgrade abrt-addon-ccppUpgrade libreport-develUpgrade abrt-addon-kerneloopsUpgrade libreport-compatUpgrade abrt-gui-libsUpgrade abrt-cliUpgrade libreport-filesystemUpgrade libreport-plugin-reportuploaderUpgrade abrt-desktopUpgrade libreport-anacondaUpgrade libreport-newtUpgrade libreport-rhel-anaconda-bugzillaUpgrade libreport-plugin-logger | Oct 16, 2024 | Dec 7, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub