VDB

CVE-2020-15396

CVE-2020-15396 PUBLISHED

In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.

EPSS 0.04% · 11.6th percentile

Risk Scores

EPSS Score
0.04%
11.6th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTShylafax3:6.0.7-7, 3:6.0.7-5build1, 0
Ubuntu:18.04:LTShylafax3:6.0.6-8, 0, 3:6.0.6-8.1~ubuntu0.18.04.1
Ubuntu:20.04:LTShylafax0, *
Ubuntu:22.04:LTShylafax0, 3:6.0.7-3.1
Ubuntu:16.04:LTShylafax3:6.0.6-6, 0, 3:6.0.6-6+deb8u1build0.16.04.1
Ubuntu:25.10hylafax*, *, 0

Timeline

  • Jun 30, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 22, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 25, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 27, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 2, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 5, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›