In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade hylafaxplus | Aug 10, 2020 | Jun 30, 2020 |
| Debian | — | Upgrade hylafax | Jul 30, 2024 | Jun 30, 2020 |
| Gentoo Linux | — | Upgrade net-misc/hylafaxplus. | Jul 28, 2020 | Jun 30, 2020 |
| Suse | — | Upgrade hylafax+-clientUpgrade hylafax+Upgrade libfaxutil7_0_3 | Aug 15, 2020 | Jun 30, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub