CVE-2020-15396

Name
CVE-2020-15396
Description
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://bugzilla.suse.com/show_bug.cgi?id=1173521
Patch https://sourceforge.net/p/hylafax/HylaFAX+/2534/
GENTOO https://security.gentoo.org/glsa/202007-06
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y46FOVJUS5SO44A2VEKR7DXEHTI4WK5L/
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00039.html
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J52QFVREJWJ35YSEEDDRMZQ2LM2H2WE6/
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00040.html
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00046.html
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00054.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:hylafax\+_project:hylafax\+:*:*:*:*:*:*:*:* hylafax\+ >= None <= 7.0.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
hylafaxplus edge-main 7.0.2-r2 None fixed
hylafaxplus edge-community 7.0.2-r2 None fixed
hylafaxplus 3.22-community 7.0.2-r2 None fixed
hylafaxplus 3.21-community 7.0.2-r2 None fixed
hylafaxplus 3.20-main 7.0.2-r2 None fixed
hylafaxplus 3.19-main 7.0.2-r2 None fixed
hylafaxplus 3.18-main 7.0.2-r2 None fixed
hylafaxplus 3.17-main 7.0.2-r2 None fixed
hylafaxplus 3.12-main 7.0.2-r2 Francesco Colista <fcolista@alpinelinux.org> fixed
hylafaxplus 3.11-main 7.0.1-r2 Francesco Colista <fcolista@alpinelinux.org> fixed
hylafaxplus 3.10-main 7.0.0-r4 Francesco Colista <fcolista@alpinelinux.org> fixed