CVE-2015-5273

medium

Description

The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users to write to arbitrary files via a symlink attack on unpacked.cpio in a pre-created directory with a predictable name in /var/tmp.

References

https://github.com/abrt/abrt/commit/50ee8130fb4cd4ef1af7682a2c85dd99cb99424e

http://www.securityfocus.com/bid/78113

http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html

http://rhn.redhat.com/errata/RHSA-2015-2505.html

http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172809.html

Details

Source: Mitre, NVD

Published: 2015-12-07

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:P

Severity: Low

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Severity: Medium