The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle_linux | — | Upgrade libreport-plugin-reportuploaderUpgrade abrt-retrace-clientUpgrade abrt-addon-ccppUpgrade libreport-plugin-kerneloopsUpgrade abrtUpgrade abrt-desktopUpgrade libreport-anacondaUpgrade abrt-addon-upload-watchUpgrade abrt-develUpgrade libreport-plugin-mailxUpgrade libreport-pythonUpgrade libreport-develUpgrade abrt-addon-pythonUpgrade libreport-plugin-loggerUpgrade libreport-rhel-bugzillaUpgrade libreport-web-develUpgrade libreportUpgrade libreport-plugin-bugzillaUpgrade abrt-gui-libsUpgrade abrt-cliUpgrade abrt-addon-kerneloopsUpgrade libreport-compatUpgrade libreport-rhel-anaconda-bugzillaUpgrade libreport-newtUpgrade abrt-dbusUpgrade libreport-plugin-ureportUpgrade libreport-filesystemUpgrade libreport-gtk-develUpgrade abrt-console-notificationUpgrade libreport-webUpgrade abrt-python-docUpgrade abrt-guiUpgrade abrt-addon-pstoreoopsUpgrade abrt-addon-vmcoreUpgrade abrt-addon-xorgUpgrade abrt-gui-develUpgrade abrt-pythonUpgrade abrt-libsUpgrade abrt-tuiUpgrade libreport-cliUpgrade libreport-gtk | Oct 16, 2024 | Dec 7, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub