← 戻る
CVE-2015-1862
high
CVSS 7.0
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve...
概要
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve...
AI要約 openai / gpt-4o
Abrtのクラッシュレポート機能において、ローカルユーザーが命名空間環境でのchrootの後にrootのexecveを利用して特権を取得することが可能です。この問題は、高い深刻度として分類されており、ローカルでの権限昇格を引き起こす可能性があります。
❓ 何が問題か
Abrtにおけるクラッシュレポート機能の脆弱性です。
📍 影響範囲
Abrtのクラッシュレポート機能を持つシステム。
🔥 重要度
ローカルユーザーが特権を取得できるため、システムの安全性が脅かされます。
🔧 修正方法
新しいバージョンにアップデートし、脆弱性を修正したパッチを適用してください。
🛡️ 暫定回避
情報なし
🔍 検知方法
パッチが適用されているか、システムのバージョンを確認してください。
参照URL
- exploit af854a3a-2127-422b-91ae-364da2661108
- exploit af854a3a-2127-422b-91ae-364da2661108
- web http://packetstormsecurity.com/files/131422/Fedora-abrt-Race-Condition.html
- web http://packetstormsecurity.com/files/131423/Linux-Apport-Abrt-Local-Root-Exploit.html
- web http://packetstormsecurity.com/files/131429/Abrt-Apport-Race-Condition-Symlink.html
- web http://seclists.org/fulldisclosure/2015/Apr/34
- web http://www.openwall.com/lists/oss-security/2015/04/14/4
- web http://www.securityfocus.com/bid/74263
- web https://bugzilla.redhat.com/show_bug.cgi?id=1211223
- web https://github.com/abrt/abrt/pull/810
- web https://nvd.nist.gov/vuln/detail/CVE-2015-1862
- web https://www.exploit-db.com/exploits/36746
- web https://www.exploit-db.com/exploits/36747
- web https://github.com/advisories/GHSA-vwwv-5cgp-6jw3