CVE-2015-3159: Red Hat Automatic Bug Reporting Tool

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) does not properly handle the process environment before invoking abrt-action-install-debuginfo, which allows local users to gain privileges.

Affected products

  • Red Hat Automatic Bug Reporting Tool: affected versions not specified

Published 2020-01-14. Last modified 2026-06-17.