vendor:
Enterprise Linux
by:
rebel
7,2
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: Enterprise Linux
Affected Version From: 7.0
Affected Version To: 7.1
Patch Exists: YES
Related CWE: CVE-2015-5287
CPE: o:redhat:enterprise_linux:7.1
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2015
abrt/sosreport RHEL 7.0/7.1 local root
This exploit is a local privilege escalation vulnerability in abrt/sosreport in Red Hat Enterprise Linux (RHEL) 7.0 and 7.1. It allows a local user to gain root privileges by exploiting a race condition in the abrt/sosreport component. The vulnerability is triggered when a local user creates a symbolic link in the /proc/sys/kernel/modprobe file, which points to a malicious script. The malicious script is then executed with root privileges when the sosreport utility is run.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should upgrade to the latest version of abrt/sosreport.