Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wg48-gxwc-c947

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.

In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.

EPSS

Процентиль: 22%
0.00073
Низкий

7.8 High

CVSS3

Дефекты

CWE-269
CWE-362

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 5 лет назад

In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.

CVSS3: 7.8
nvd
больше 5 лет назад

In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.

CVSS3: 7.8
debian
больше 5 лет назад

In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility ...

suse-cvrf
больше 5 лет назад

Security update for hylafax+

suse-cvrf
больше 5 лет назад

Security update for hylafax+

EPSS

Процентиль: 22%
0.00073
Низкий

7.8 High

CVSS3

Дефекты

CWE-269
CWE-362