← Retour
CVE-2015-1862
high
CVSS 7.0
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve...
Résumé
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve...
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2015-1862** a été découverte dans redhat.
L'exploitation peut entraîner la prise de contrôle totale du système. Score CVSS : 7.0/10.
Action : appliquez le correctif officiel de l'éditeur.
En cas de doute, contactez votre service informatique ou cherchez « redhat CVE-2015-1862 » sur le site de l'éditeur.
CVE-2015-1862 (redhat) — CWE-362 / CVSS v3 7.0
Vecteur d'attaque : local / sans interaction utilisateur
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
Abrtにおけるクラッシュレポート機能の脆弱性です。
📍 Périmètre concerné
Abrtのクラッシュレポート機能を持つシステム。
🔥 Gravité
ローカルユーザーが特権を取得できるため、システムの安全性が脅かされます。
🔧 Comment corriger
新しいバージョンにアップデートし、脆弱性を修正したパッチを適用してください。
🛡️ Contournement
情報なし
🔍 Détection
パッチが適用されているか、システムのバージョンを確認してください。
Références
- exploit af854a3a-2127-422b-91ae-364da2661108
- exploit af854a3a-2127-422b-91ae-364da2661108
- web http://packetstormsecurity.com/files/131422/Fedora-abrt-Race-Condition.html
- web http://packetstormsecurity.com/files/131423/Linux-Apport-Abrt-Local-Root-Exploit.html
- web http://packetstormsecurity.com/files/131429/Abrt-Apport-Race-Condition-Symlink.html
- web http://seclists.org/fulldisclosure/2015/Apr/34
- web http://www.openwall.com/lists/oss-security/2015/04/14/4
- web http://www.securityfocus.com/bid/74263
- web https://bugzilla.redhat.com/show_bug.cgi?id=1211223
- web https://github.com/abrt/abrt/pull/810
- web https://nvd.nist.gov/vuln/detail/CVE-2015-1862
- web https://www.exploit-db.com/exploits/36746
- web https://www.exploit-db.com/exploits/36747
- web https://github.com/advisories/GHSA-vwwv-5cgp-6jw3