CVE-2015-5287

Executive Summary

The CVE-2015-5287 vulnerability in ABRT’s abrt-hook-ccpp allows local users with sufficient permissions to perform a symlink attack on predictable temporary files (e.g., /var/tmp/abrt/abrt-hax-coredump). By creating a malicious symlink, an attacker can cause the helper program to follow the link and write to arbitrary locations, effectively escalating privileges. The flaw is actively exploited in the wild, as identified by CISA’s KEV list, and requires local access to the affected system.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2015-12-07T18:59:02.230 - Last Modified: 2026-08-27T04:16:38.280

[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2026-08-26)

Original Description: The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.

"Genuine love should first be directed at oneself � if we do not love ourselves, how can we love others?"

— Dalai Lama
Source: NVD