{"id":"MGASA-2020-0356","summary":"Updated hylafax+ packages fix security vulnerabilities","details":"In HylaFAX+ through 7.0.2, the faxsetup utility calls chown on files in\nuser-owned directories. By winning a race, a local attacker could use this to\nescalate his privileges to root (CVE-2020-15396).\n\nHylaFAX+ through 7.0.2 has scripts that execute binaries from directories\nwritable by unprivileged users (e.g., locations under /var/spool/hylafax that\nare writable by the uucp account). This allows these users to execute code in\nthe context of the user calling these binaries (often root) (CVE-2020-15397).\n\nThe hylafax+ package has been updated to version 7.0.3, fixing thesee issues\nand several other bugs.\n","modified":"2026-04-16T04:43:54.033672811Z","published":"2020-08-31T23:58:35Z","upstream":["CVE-2020-15396","CVE-2020-15397"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0356.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=27170"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/J52QFVREJWJ35YSEEDDRMZQ2LM2H2WE6/"},{"type":"WEB","url":"https://hylafax.sourceforge.io/news/7.0.3.php"}],"affected":[{"package":{"name":"hylafax+","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/hylafax+?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"+-7.0.3-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0356.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}