vendor:
N/A
by:
taviso@cmpxchg8b.com
7
CVSS
HIGH
Apport: CVE-2015-1318, Abrt: CVE-2015-1862
264
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: No
Related CWE: CVE-2015-1318, CVE-2015-1862
CPE: N/A
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=82792, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/linux/local/apport_abrt_chroot_priv_esc, https://www.infosecmatter.com/nessus-plugin-library/?id=88587, https://www.infosecmatter.com/nessus-plugin-library/?id=86909, https://www.infosecmatter.com/nessus-plugin-library/?id=89181, https://www.infosecmatter.com/nessus-plugin-library/?id=83238, https://www.infosecmatter.com/nessus-plugin-library/?id=83422, https://www.infosecmatter.com/nessus-plugin-library/?id=88629, https://www.infosecmatter.com/nessus-plugin-library/?id=81944, https://www.infosecmatter.com/nessus-plugin-library/?id=93169, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/linux/local/abrt_raceabrt_priv_esc, https://www.infosecmatter.com/nessus-plugin-library/?id=84878, https://www.infosecmatter.com/nessus-plugin-library/?id=80043, https://www.infosecmatter.com/nessus-plugin-library/?id=72688, https://www.infosecmatter.com/list-of-metasploit-linux-exploits-detailed-spreadsheet/
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2015
Apport/Abrt Vulnerability Demo Exploit
This exploit is used to gain root access by exploiting the Apport and Abrt vulnerabilities. It checks for a dynamic segment in the program headers and if found, it exits with an error. If not found, it checks if the user is root and if so, it creates a setuid root executable. If the user is not root but the effective user id is 0, then it spawns a shell and cleans up the exploit. Otherwise, it exits with an error.
Mitigation:
The best way to mitigate this vulnerability is to ensure that all programs are compiled with the -static flag and that all setuid root executables are properly audited.