{"id":"CVE-2015-5287","title":"The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/a…","summary":"The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/a…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-59","CWE-59"],"vendor":"redhat","product":"automatic_bug_reporting_tool","affected":["automatic_bug_reporting_tool <= 2.7.0","enterprise_linux_desktop = 7.0","enterprise_linux_hpc_node = 7.0","enterprise_linux_server = 7.0","enterprise_linux_workstation = 7.0"],"published":"2015-12-07","updated":"2026-08-26","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2015-5287","references":[{"url":"http://packetstormsecurity.com/files/154592/ABRT-sosreport-Privilege-Escalation.html","label":"secalert@redhat.com"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-2505.html","label":"secalert@redhat.com"},{"url":"http://www.openwall.com/lists/oss-security/2015/12/01/1","label":"secalert@redhat.com"},{"url":"http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html","label":"secalert@redhat.com"},{"url":"http://www.securityfocus.com/bid/78137","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1266837","label":"secalert@redhat.com"},{"url":"https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e","label":"secalert@redhat.com"},{"url":"https://www.exploit-db.com/exploits/38832/","label":"secalert@redhat.com"},{"url":"http://packetstormsecurity.com/files/154592/ABRT-sosreport-Privilege-Escalation.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-2505.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2015/12/01/1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/78137","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1266837","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.exploit-db.com/exploits/38832/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-5287","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.04962,"epssPercentile":0.91832,"kev":true,"kevDateAdded":"2026-08-26","kevDueDate":"2026-09-09","kevRansomware":false,"exploited":true,"exploitAvailable":true,"ingestedAt":"2026-08-26T18:47:53.401Z","exploits":{"exploitdb":true,"github":1,"githubRepos":["https://github.com/HORKimhab/CVE-2015-5287"],"metasploit":["exploit/linux/local/abrt_sosreport_priv_esc"],"checkedAt":"2026-09-21T15:23:33.844Z"},"slug":"CVE-2015-5287","body":"## Overview\n\nThe abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.\n\n## Affected\n\n- `automatic_bug_reporting_tool <= 2.7.0`\n- `enterprise_linux_desktop = 7.0`\n- `enterprise_linux_hpc_node = 7.0`\n- `enterprise_linux_server = 7.0`\n- `enterprise_linux_workstation = 7.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":69,"depthScoreParts":{"impact":42.9,"likelihood":1,"exploitation":25,"ransomware":0},"changes":[]}