7.8

CVE-2020-15396

Exploit
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hylafax+ Project ≫ Hylafax+ Version <= 7.0.2
Ifax ≫ Hylafax Enterprise Version -
Fedoraproject ≫ Fedora Version 31
Fedoraproject ≫ Fedora Version 32
Opensuse ≫ Backports Sle Version 15.0 Update sp1
Opensuse ≫ Backports Sle Version 15.0 Update sp2
Opensuse ≫ Leap Version 15.1
Opensuse ≫ Leap Version 15.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.306
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00039.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00040.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00046.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00054.html
Third Party Advisory
Mailing List
https://bugzilla.suse.com/show_bug.cgi?id=1173521
Third Party Advisory
Exploit
Issue Tracking
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J52QFVREJWJ35YSEEDDRMZQ2LM2H2WE6/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y46FOVJUS5SO44A2VEKR7DXEHTI4WK5L/
https://security.gentoo.org/glsa/202007-06
Third Party Advisory
https://sourceforge.net/p/hylafax/HylaFAX+/2534/
Patch
Third Party Advisory