CVE-2015-1862 EXPLOIT
7.0
HIGH · CVSS 3.0 · EPSS 3% (pctl 87)
Patch early
A public exploit exists.
Description
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directory in a namedspaced environment.
Scoring
| CVSS | 7.0 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.02% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-362 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-02-09 |
| Last modified | 2026-08-26 |
Affected (1)
| Vendor | Product |
|---|---|
| redhat | automatic bug reporting tool |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apport/Abrt (Ubuntu / Fedora) - Local Privilege Escalation | 2015-04-14 |
| exploit-db | Abrt (Fedora 21) - Race Condition | 2015-04-14 |
References
- http://packetstormsecurity.com/files/131422/Fedora-abrt-Race-Condition.html
- http://packetstormsecurity.com/files/131423/Linux-Apport-Abrt-Local-Root-Exploit.html
- http://packetstormsecurity.com/files/131429/Abrt-Apport-Race-Condition-Symlink.html
- http://seclists.org/fulldisclosure/2015/Apr/34
- http://www.openwall.com/lists/oss-security/2015/04/14/4
- http://www.securityfocus.com/bid/74263
- https://bugzilla.redhat.com/show_bug.cgi?id=1211223
- https://github.com/abrt/abrt/pull/810
- https://www.exploit-db.com/exploits/36746/
- https://www.exploit-db.com/exploits/36747/
- http://packetstormsecurity.com/files/131422/Fedora-abrt-Race-Condition.html
- http://packetstormsecurity.com/files/131423/Linux-Apport-Abrt-Local-Root-Exploit.html
- http://packetstormsecurity.com/files/131429/Abrt-Apport-Race-Condition-Symlink.html
- http://seclists.org/fulldisclosure/2015/Apr/34
- http://www.openwall.com/lists/oss-security/2015/04/14/4
- http://www.securityfocus.com/bid/74263
- https://bugzilla.redhat.com/show_bug.cgi?id=1211223
- https://github.com/abrt/abrt/pull/810
- https://www.exploit-db.com/exploits/36746/
- https://www.exploit-db.com/exploits/36747/
→ the Explorer · watch your stack · NVD