Description
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a symlink attack on (1) /var/tmp/abrt/*/maps, (2) /tmp/jvm-*/hs_error.log, (3) /proc/*/exe, (4) /etc/os-release in a chroot, or (5) an unspecified root directory related to librpm.
In plain language
AI Worth attentionCVE-2015-3315 is a local security flaw in the automatic bug reporting tool (ABRT) that can let a normal user use a symlink trick to read or change ownership of arbitrary files; most small businesses should worry only if ABRT is installed and the tool runs with higher privileges.
CVE-2015-3315 is a symlink-following flaw (CWE-59) in automatic bug reporting tool (ABRT) that allows a local user to exploit a symlink race/direct symlink creation in shared temporary directories so the privileged ABRT process reads, changes ownership, or otherwise impacts files outside the intended area.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2015-3315 and every CVE in our database. Create a free account — no credit card required.
Create Free Account