Improper Privilege Management in HylaFAX - CVE-2020-15397
Published: July 29, 2020 / Updated: August 5, 2020
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileged users (e.g., locations under /var/spool/hylafax that are writable by the uucp account). This allows these users to execute code in the context of the user calling these binaries (often root).
Affected software
Gentoo Linux
Fedora
SUSE Linux
Opensuse
hylafaxplus (Alpine package)
hylafax+
How to mitigate CVE-2020-15397
hylafaxplus (Alpine package) - update to 7.0.0-r1
hylafax+ - addressed in versions 7.0.3-1.el6, 7.0.3-1.el7, 7.0.3-1.fc31, 7.0.3-1.fc32
External References
Related Security Bulletins
- Multiple vulnerabilities in HylaFAX+
- Gentoo update for HylaFAX
- OpenSUSE Linux update for hylafax+
- OpenSUSE Linux update for hylafax+
- OpenSUSE Linux update for hylafax+
- Improper Privilege Management in hylafaxplus (Alpine package)
- OpenSUSE Linux update for hylafax+
- Fedora EPEL 7 update for hylafax+
- Fedora EPEL 6 update for hylafax+
- Fedora 32 update for hylafax+
- Fedora 31 update for hylafax+