CVE-2015-1862
HIGHabrt < 2.2.0 - Local Privilege Escalation via Race Condition in Crash Reporting
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2015-1862. PoCs published by Tavis Ormandy.
AI-analyzed exploit summary This exploit leverages a race condition in ABRT (Automatic Bug Reporting Tool) on Fedora 21 to gain ownership of arbitrary files by manipulating symlinks during crash report generation. It uses inotify to monitor ABRT's temporary directory and attempts to replace the 'maps' file with a symlink to the target file.
Description
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directory in a namedspaced environment.
Exploits (2)
This exploit leverages a race condition in ABRT (Automatic Bug Reporting Tool) on Fedora 21 to gain ownership of arbitrary files by manipulating symlinks during crash report generation. It uses inotify to monitor ABRT's temporary directory and attempts to replace the 'maps' file with a symlink to the target file.
This exploit leverages CVE-2015-1862 in Abrt (and CVE-2015-1318 in Apport) by creating a chroot environment with hard links to the exploit binary, then triggering a core dump in a new PID/user namespace to gain root privileges. It checks for static compilation and spawns a root shell upon successful exploitation.
References (10)
Scores
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H