First published: Mon Apr 13 2015(Updated: )
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directory in a namedspaced environment.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Abrt Project Abrt | <=2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-1862 is rated as high with a severity score of 7.
To fix CVE-2015-1862, update Abrt to version 2.2.1 or later.
CVE-2015-1862 affects Abrt versions up to and including 2.2.0.
CVE-2015-1862 is a privilege escalation vulnerability.
CVE-2015-1862 can be exploited by local users leveraging an execve by root after a chroot into a user-specified directory in a namespaced environment.