Description
A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local attackers to escalate from user uucp to users calling hylafax binaries. This issue affects: openSUSE Leap 15.2 hylafax+ versions prior to 7.0.2-lp152.2.1. openSUSE Leap 15.1 hylafax+ version 5.6.1-lp151.3.7 and prior versions. openSUSE Factory hylafax+ versions prior to 7.0.2-2.1.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-28936 | A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local attackers to escalate from user uucp to users calling hylafax binaries. This issue affects: openSUSE Leap 15.2 hylafax+ versions prior to 7.0.2-lp152.2.1. openSUSE Leap 15.1 hylafax+ version 5.6.1-lp151.3.7 and prior versions. openSUSE Factory hylafax+ versions prior to 7.0.2-2.1. |
References
History
Tue, 17 Sep 2024 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Problematic permissions in hylafax+ packaging allow escalation from uucp to other users | Problematic permissions in hylafax+ packaging allow escalation from uucp to other users |
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2024-09-17T01:21:22.130Z
Reserved: 2020-01-27T00:00:00.000Z
Link: CVE-2020-8024
No data.
Status : Modified
Published: 2020-06-29T08:15:10.050
Modified: 2024-11-21T05:38:14.550
Link: CVE-2020-8024
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD