HylaFAX+ Project HylaFAX+ 5.5.3

CPE Details

HylaFAX+ Project HylaFAX+ 5.5.3
5.5.3
2020-08-17
10h34 +00:00
2020-08-17
10h34 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:hylafax\+_project:hylafax\+:5.5.3:*:*:*:*:*:*:*

Informations

Vendor

hylafax\+_project

Product

hylafax\+

Version

5.5.3

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2020-15397 2020-06-30 09h17 +00:00 HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileged users (e.g., locations under /var/spool/hylafax that are writable by the uucp account). This allows these users to execute code in the context of the user calling these binaries (often root).
7.8
Haute
CVE-2020-15396 2020-06-30 09h17 +00:00 In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
7.8
Haute