The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle_linux | — | Upgrade abrt-libsUpgrade libreport-cliUpgrade abrt-pythonUpgrade libreport-gtkUpgrade abrt-tuiUpgrade libreport-webUpgrade abrt-console-notificationUpgrade abrt-python-docUpgrade abrt-gui-develUpgrade abrt-addon-xorgUpgrade abrt-guiUpgrade libreport-gtk-develUpgrade abrt-addon-vmcoreUpgrade abrt-addon-pstoreoopsUpgrade abrt-addon-kerneloopsUpgrade libreport-rhel-anaconda-bugzillaUpgrade libreport-plugin-bugzillaUpgrade abrt-addon-pythonUpgrade libreport-develUpgrade libreport-compatUpgrade abrt-dbusUpgrade libreport-web-develUpgrade abrtUpgrade abrt-desktopUpgrade libreport-plugin-loggerUpgrade libreport-plugin-kerneloopsUpgrade libreport-anacondaUpgrade abrt-gui-libsUpgrade abrt-addon-ccppUpgrade abrt-addon-upload-watchUpgrade libreport-pythonUpgrade libreport-filesystemUpgrade libreportUpgrade abrt-retrace-clientUpgrade libreport-rhel-bugzillaUpgrade libreport-newtUpgrade abrt-cliUpgrade libreport-plugin-reportuploaderUpgrade libreport-plugin-ureportUpgrade abrt-develUpgrade libreport-plugin-mailx | Oct 16, 2024 | Dec 7, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub