Upstream information

CVE-2015-5287 at MITRE

Description

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 6.9
Vector AV:L/AC:M/Au:N/C:C/I:C/A:C
Access Vector Local
Access Complexity Medium
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE Liberty Linux 7
  • abrt >= 2.1.11-35.el7
  • abrt-addon-ccpp >= 2.1.11-35.el7
  • abrt-addon-kerneloops >= 2.1.11-35.el7
  • abrt-addon-pstoreoops >= 2.1.11-35.el7
  • abrt-addon-python >= 2.1.11-35.el7
  • abrt-addon-upload-watch >= 2.1.11-35.el7
  • abrt-addon-vmcore >= 2.1.11-35.el7
  • abrt-addon-xorg >= 2.1.11-35.el7
  • abrt-cli >= 2.1.11-35.el7
  • abrt-console-notification >= 2.1.11-35.el7
  • abrt-dbus >= 2.1.11-35.el7
  • abrt-desktop >= 2.1.11-35.el7
  • abrt-devel >= 2.1.11-35.el7
  • abrt-gui >= 2.1.11-35.el7
  • abrt-gui-devel >= 2.1.11-35.el7
  • abrt-gui-libs >= 2.1.11-35.el7
  • abrt-libs >= 2.1.11-35.el7
  • abrt-python >= 2.1.11-35.el7
  • abrt-python-doc >= 2.1.11-35.el7
  • abrt-retrace-client >= 2.1.11-35.el7
  • abrt-tui >= 2.1.11-35.el7
  • libreport >= 2.1.11-31.el7
  • libreport-anaconda >= 2.1.11-31.el7
  • libreport-cli >= 2.1.11-31.el7
  • libreport-compat >= 2.1.11-31.el7
  • libreport-devel >= 2.1.11-31.el7
  • libreport-filesystem >= 2.1.11-31.el7
  • libreport-gtk >= 2.1.11-31.el7
  • libreport-gtk-devel >= 2.1.11-31.el7
  • libreport-newt >= 2.1.11-31.el7
  • libreport-plugin-bugzilla >= 2.1.11-31.el7
  • libreport-plugin-kerneloops >= 2.1.11-31.el7
  • libreport-plugin-logger >= 2.1.11-31.el7
  • libreport-plugin-mailx >= 2.1.11-31.el7
  • libreport-plugin-reportuploader >= 2.1.11-31.el7
  • libreport-python >= 2.1.11-31.el7
  • libreport-web >= 2.1.11-31.el7
  • libreport-web-devel >= 2.1.11-31.el7
Patchnames:
RHSA-2015:2505


SUSE Timeline for this CVE

CVE page created: Mon Nov 23 10:42:41 2015
CVE page last modified: Mon Oct 30 17:17:41 2023