Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-3315

38
FAUCET Score

CVE-2015-3315 describes a local privilege escalation vulnerability in the Automatic Bug Reporting Tool (ABRT) affecting various Red Hat Enterprise Linux products. This flaw allows a local attacker to perform a symlink attack on specific files and directories, leading to arbitrary file reading, ownership changes, or other unspecified impacts. With a CVSSv3 score of 7.8 (High), the vulnerability has a low attack complexity and requires local access, but can result in high confidentiality, integrity, and availability impacts. Exploit code is publicly available, including a Metasploit module, though there is no evidence of active exploitation in the wild and minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:redhat:automatic_bug_reporting_tool:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.8HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
4.78%
Probability of exploitation in next 30 days
EPSS Percentile
91.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Metasploit: ABRT raceabrt Privilege Escalation · Apr 14, 2015
ExploitDB: EDB-44097 · Feb 16, 2018
This CVE's current EPSS score of 0.0478 is in the 98th percentile among its peer group of 16,994 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: abrt-0:2.0.8-26.el6_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: libreport-0:2.0.9-21.el6_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: abrt-0:2.1.11-22.el7_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: libreport-0:2.1.11-23.el7_1
View patch

Vendor Advisories (1)

redhatCVE-2015-3315Important

abrt: Various race-conditions and symlink issues found in abrt

Apr 14, 2015

References

rhn.redhat.com / errata/RHSA-2015-1083.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1210.html
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party AdvisoryVDB Entry
github.com / abrt/abrt/commit/17cb66b13997b0159b4253b3f5722db79f476d68
PatchThird Party Advisory
github.com / abrt/abrt/commit/4f2c1ddd3e3b81d2d5146b883115371f1cada9f9
PatchThird Party Advisory
github.com / abrt/abrt/commit/80408e9e24a1c10f85fd969e1853e0f192157f92
PatchThird Party Advisory
github.com / abrt/abrt/commit/d6e2f6f128cef4c21cb80941ae674c9842681aa7
PatchThird Party Advisory
exploit-db.com / exploits/44097
openwall.com / lists/oss-security/2015/04/14/4
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2015/04/16/12
Mailing ListThird Party Advisory
securityfocus.com / bid/75117
Third Party AdvisoryVDB Entry