Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26166
HistoryAug 06, 2020 - 9:34 p.m.

Arbitrary Code Execution

2020-08-0621:34:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
arbitrary code execution
hylafax+
vulnerability
scripts
binaries
directories
unprivileged users
writable
uucp account
context execution
root access

EPSS

0.001

Percentile

45.0%

hylafaxplus is vulnerable to arbitrary code execution. The vulnerability exists as HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileged users (e.g., locations under /var/spool/hylafax that are writable by the uucp account). This allows these users to execute code in the context of the user calling these binaries (often root).