Upstream information
CVE-2015-5287 at MITRE
Description
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having moderate severity.
CVSS v2 Scores
| CVSS detail |  National Vulnerability Database | 
| Base Score |  6.9 | 
| Vector |  AV:L/AC:M/Au:N/C:C/I:C/A:C | 
| Access Vector |  Local | 
| Access Complexity |  Medium | 
| Authentication |  None | 
| Confidentiality Impact |  Complete | 
| Integrity Impact |  Complete | 
| Availability Impact |  Complete | 
No SUSE Bugzilla entries cross referenced.
No SUSE Security Announcements cross referenced.
List of released packages
| Product(s) |  Fixed package version(s) |  References | 
| SUSE Liberty Linux 7 |  abrt >= 2.1.11-35.el7 
 abrt-addon-ccpp >= 2.1.11-35.el7 
 abrt-addon-kerneloops >= 2.1.11-35.el7 
 abrt-addon-pstoreoops >= 2.1.11-35.el7 
 abrt-addon-python >= 2.1.11-35.el7 
 abrt-addon-upload-watch >= 2.1.11-35.el7 
 abrt-addon-vmcore >= 2.1.11-35.el7 
 abrt-addon-xorg >= 2.1.11-35.el7 
 abrt-cli >= 2.1.11-35.el7 
 abrt-console-notification >= 2.1.11-35.el7 
 abrt-dbus >= 2.1.11-35.el7 
 abrt-desktop >= 2.1.11-35.el7 
 abrt-devel >= 2.1.11-35.el7 
 abrt-gui >= 2.1.11-35.el7 
 abrt-gui-devel >= 2.1.11-35.el7 
 abrt-gui-libs >= 2.1.11-35.el7 
 abrt-libs >= 2.1.11-35.el7 
 abrt-python >= 2.1.11-35.el7 
 abrt-python-doc >= 2.1.11-35.el7 
 abrt-retrace-client >= 2.1.11-35.el7 
 abrt-tui >= 2.1.11-35.el7 
 libreport >= 2.1.11-31.el7 
 libreport-anaconda >= 2.1.11-31.el7 
 libreport-cli >= 2.1.11-31.el7 
 libreport-compat >= 2.1.11-31.el7 
 libreport-devel >= 2.1.11-31.el7 
 libreport-filesystem >= 2.1.11-31.el7 
 libreport-gtk >= 2.1.11-31.el7 
 libreport-gtk-devel >= 2.1.11-31.el7 
 libreport-newt >= 2.1.11-31.el7 
 libreport-plugin-bugzilla >= 2.1.11-31.el7 
 libreport-plugin-kerneloops >= 2.1.11-31.el7 
 libreport-plugin-logger >= 2.1.11-31.el7 
 libreport-plugin-mailx >= 2.1.11-31.el7 
 libreport-plugin-reportuploader >= 2.1.11-31.el7 
 libreport-python >= 2.1.11-31.el7 
 libreport-web >= 2.1.11-31.el7 
 libreport-web-devel >= 2.1.11-31.el7 
  |  Patchnames:  RHSA-2015:2505 | 
SUSE Timeline for this CVE
CVE page created: Mon Nov 23 10:42:41 2015
CVE page last modified: Mon Oct  6 18:23:10 2025