The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle_linux | — | Upgrade libreport-plugin-loggerUpgrade libreport-plugin-ureportUpgrade abrt-desktopUpgrade abrt-retrace-clientUpgrade libreportUpgrade libreport-newtUpgrade abrt-addon-upload-watchUpgrade abrtUpgrade libreport-rhel-bugzillaUpgrade libreport-plugin-bugzillaUpgrade abrt-addon-ccppUpgrade abrt-gui-libsUpgrade libreport-compatUpgrade abrt-develUpgrade abrt-addon-pythonUpgrade abrt-dbusUpgrade libreport-anacondaUpgrade libreport-plugin-mailxUpgrade abrt-cliUpgrade libreport-filesystemUpgrade libreport-develUpgrade libreport-pythonUpgrade abrt-addon-kerneloopsUpgrade libreport-rhel-anaconda-bugzillaUpgrade libreport-plugin-reportuploaderUpgrade libreport-plugin-kerneloopsUpgrade libreport-web-develUpgrade abrt-pythonUpgrade abrt-tuiUpgrade libreport-webUpgrade abrt-addon-pstoreoopsUpgrade abrt-libsUpgrade abrt-gui-develUpgrade abrt-console-notificationUpgrade abrt-addon-xorgUpgrade abrt-guiUpgrade abrt-addon-vmcoreUpgrade libreport-gtk-develUpgrade libreport-cliUpgrade libreport-gtkUpgrade abrt-python-doc | Oct 16, 2024 | Dec 7, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub