Executive brief
Red Hat's Automatic Bug Reporting Tool (ABRT) is a system component that collects and reports application crash information to assist with debugging. A local privilege escalation vulnerability allows users with basic system access to gain elevated privileges by exploiting predictable file names and symlink attacks, potentially compromising system security and enabling unauthorized access to sensitive system functions.
Technical details
CVE-2015-5287 is a privilege escalation vulnerability in Red Hat ABRT that exploits a symlink race condition on predictably named temporary files. The vulnerability allows a local attacker with user-level privileges to create symbolic links that redirect privileged file operations to arbitrary system locations. By leveraging this race condition, an attacker can achieve privilege escalation and execute arbitrary commands with elevated permissions. The attack requires local access to the system but does not require prior authentication to ABRT itself. This vulnerability has been exploited in the wild, indicating active attacks. While ABRT is noted as potentially end-of-life or end-of-service, users should apply patches or discontinue use of affected versions.
Affected products
- Red Hat Automatic Bug Reporting Tool (ABRT)
Timeline
- 2015: disclosed: CVE-2015-5287 disclosed
- exploited: Known to be exploited in the wild