← Terug naar overzicht

CVE-2015-5287 is a privilege escalation vulnerability in Red Hat's Automatic Bug Reporting Tool (ABRT). It allows local users with certain permissions to gain elevated privileges by performing a symlink attack on a file with a predictable name. The vulnerability affects an open-source component that may be used across multiple products. The impacted product(s) may be end-of-life or end-of-service, and users are advised to discontinue use or transition to a supported version. A fix is referenced in the ABRT GitHub repository. CISA has flagged this vulnerability under BOD 26-04, which prioritizes security updates based on risk. Forensic triage guidance is also available through CISA's BOD 26-04 implementation resources. The NVD entry confirms the severity and details of this vulnerability.

Affected products

  • Red Hat Automatic Bug Reporting Tool (ABRT)

Related CVE's

  • CVE-2015-5287

Categories

  • Identity & Access
  • Operating Systems
  • Supply Chain & Dependencies