CVE-2015-5287: Medium severity red hat automatic bug reporting tool vulnerability
A vulnerability allowing to elevate privileges from the abrt user to root was reported. If a program starting with the name "abrt" crashes, abrt-hook-ccpp will write the coredump to /var/tmp/abrt/$filename-coredump or /var/spool/abrt/$filename-coredump. From abrt-hook-ccpp.c:
if (lastslash && strncmp(++lastslash, "abrt", 4) == 0) { / If abrtd/abrt-foo crashes, we don't want to create a directory, since that can make new copy of abrtd to process it, and maybe crash again... Unlike dirs, mere files are ignored by abrtd. / if (snprintf(path, sizeof(path), "%s/%s-coredump", gsettingsdumplocation, lastslash) >= sizeof(path)) errormsganddie("Error saving '%s': truncated long file path", path);
int abrtcorefd = xopen3(path, OWRONLY | OCREAT | OTRUNC, 0600);
The call to xopen3() does not include the flag ONOFOLLOW and is therefore vulnerable to a symlink attack.
This vulnerability is not exploitable on RHEL installations with default configuration. It can be exploitable if the system is configured to use non-RHN yum repositories. This is because yum is normally not usable by non-root users if the only configured repositories are RHN.
Note: This security flaw has been split from bug #1262252.
Other sources
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5287?
CVE-2015-5287 has a high severity rating due to its potential for privilege escalation from the abrt user to root.
How can I fix CVE-2015-5287?
To fix CVE-2015-5287, you should update the Red Hat Automatic Bug Reporting Tool to a version above 2.7.0.
Which software is affected by CVE-2015-5287?
CVE-2015-5287 affects Red Hat Automatic Bug Reporting Tool versions up to 2.7.0 and Red Hat Enterprise Linux 7.0.
What does CVE-2015-5287 allow an attacker to do?
CVE-2015-5287 allows an attacker to elevate their privileges from the abrt user to root, posing a significant security risk.
Is CVE-2015-5287 specific to certain operating systems?
Yes, CVE-2015-5287 is specifically reported for Red Hat Enterprise Linux distributions, including Workstation, Server, and HPC Node.