← 戻る
CVE-2015-5287
CISA KEV
high
CVSS 7.8
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local...
概要
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local...
AI要約 openai / gpt-4o
Red Hat Automatic Bug Reporting Toolに特権昇格の脆弱性があります。この脆弱性は、ローカルユーザーが特定の権限を持っている場合、予測可能な名前のファイルに対するシンボリックリンク攻撃を通じて特権を得ることができます。影響を受ける製品はEoLまたはEoSの可能性があり、使用を中止またはサポートされているバージョンへの移行が推奨されます。
❓ 何が問題か
Red Hat Automatic Bug Reporting Toolにおける特権昇格の脆弱性
📍 影響範囲
Red Hat Automatic Bug Reporting Tool
🔥 重要度
ユーザーはシンボリックリンク攻撃を通じて特権を取得できる
🔧 修正方法
このツールの使用を中止し、サポートされているバージョンに移行すること
🛡️ 暫定回避
情報なし
🔍 検知方法
情報なし
参照URL
- advisory af854a3a-2127-422b-91ae-364da2661108
- advisory af854a3a-2127-422b-91ae-364da2661108
- advisory af854a3a-2127-422b-91ae-364da2661108
- advisory 134c704f-9b21-4f2e-91b3-4a467353bcc0
- advisory af854a3a-2127-422b-91ae-364da2661108
- advisory 134c704f-9b21-4f2e-91b3-4a467353bcc0
- exploit af854a3a-2127-422b-91ae-364da2661108
- exploit af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- web https://nvd.nist.gov/vuln/detail/CVE-2015-5287
- web https://www.exploit-db.com/exploits/38832
- web https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations
- web https://github.com/advisories/GHSA-hf8c-7p7w-mch5