CVE-2015-3147: Red Hat Automatic Bug Reporting Tool
Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.
daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on (1) /var/spool/abrt or (2) /var/tmp/abrt.
Affected products
- Red Hat Automatic Bug Reporting Tool: affected versions not specified
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server Eus: version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; …
- Red Hat Enterprise Linux Server Tus: version 7.3 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2020-01-14. Last modified 2026-06-17.