CVE-2015-5273
Automatic Bug Reporting Tool < 2.7.1 - Arbitrary File Write via Symlink Attack on unpacked.cpio
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-5273.
AI-analyzed exploit summary This exploit leverages two CVEs (CVE-2015-5273 and CVE-2015-5287) to achieve local privilege escalation on CentOS 7.1/Fedora 22 by exploiting insecure file operations in abrt-hook-ccpp and abrt-action-install-debuginfo. It manipulates symbolic links and coredump handling to overwrite /proc/sys/kernel/modprobe, leading to root access.
Description
The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users to write to arbitrary files via a symlink attack on unpacked.cpio in a pre-created directory with a predictable name in /var/tmp.
Exploits (1)
This exploit leverages two CVEs (CVE-2015-5273 and CVE-2015-5287) to achieve local privilege escalation on CentOS 7.1/Fedora 22 by exploiting insecure file operations in abrt-hook-ccpp and abrt-action-install-debuginfo. It manipulates symbolic links and coredump handling to overwrite /proc/sys/kernel/modprobe, leading to root access.