CVE-2020-15396
30.06.2020, 12:15
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
Vendor | Product | Version |
---|---|---|
hylafax\+_project | hylafax\+ | 𝑥 ≤ 7.0.2 |
ifax | hylafax_enterprise | - |
opensuse | backports_sle | 15.0:sp1 |
opensuse | backports_sle | 15.0:sp2 |
opensuse | leap | 15.1 |
opensuse | leap | 15.2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References