CVE-2015-3159: Red Hat Automatic Bug Reporting Tool
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) does not properly handle the process environment before invoking abrt-action-install-debuginfo, which allows local users to gain privileges.
Affected products
- Red Hat Automatic Bug Reporting Tool: affected versions not specified
Published 2020-01-14. Last modified 2026-06-17.