CVE-2020-8024
published 2020-06-29CVE-2020-8024: A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local attackers…
PriorityP422medium5.3CVSS 3.1
AVLACLPRNUIRSUCLILAL
EPSS
0.49%
39.2th percentile
A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local attackers to escalate from user uucp to users calling hylafax binaries. This issue affects: openSUSE Leap 15.2 hylafax+ versions prior to 7.0.2-lp152.2.1. openSUSE Leap 15.1 hylafax+ version 5.6.1-lp151.3.7 and prior versions. openSUSE Factory hylafax+ versions prior to 7.0.2-2.1.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | hylafax | — | — |
| opensuse | hylafax | < 7.0.2-lp152.2.1 | 7.0.2-lp152.2.1 |
| opensuse | hylafax | < 5.6.1-lp151.3.7 | 5.6.1-lp151.3.7 |
| opensuse | hylafax | < 7.0.2-2.1 | 7.0.2-2.1 |
| opensuse | opensuse_factory | >= hylafax+ < 7.0.2-2.1 | 7.0.2-2.1 |
| opensuse | opensuse_leap_15.1 | hylafax+ – 5.6.1-lp151.3.7 | — |
| opensuse | opensuse_leap_15.2 | >= hylafax+ < 7.0.2-lp152.2.1 | 7.0.2-lp152.2.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv5.3MEDIUM
vendor_debian5.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rv88-x9wr-52g7: A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15
ghsa_unreviewed·2022-05-24
CVE-2020-8024 [MEDIUM] GHSA-rv88-x9wr-52g7: A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15
A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local attackers to escalate from user uucp to users calling hylafax binaries. This issue affects: openSUSE Leap 15.2 hylafax+ versions prior to 7.0.2-lp152.2.1. openSUSE Leap 15.1 hylafax+ version 5.6.1-lp151.3.7 and prior versions. openSUSE Factory hylafax+ versions prior to 7.0.2-2.1.
OSV
CVE-2020-8024: A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15
osv·2020-06-29·CVSS 5.3
CVE-2020-8024 [MEDIUM] CVE-2020-8024: A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15
A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local attackers to escalate from user uucp to users calling hylafax binaries. This issue affects: openSUSE Leap 15.2 hylafax+ versions prior to 7.0.2-lp152.2.1. openSUSE Leap 15.1 hylafax+ version 5.6.1-lp151.3.7 and prior versions. openSUSE Factory hylafax+ versions prior to 7.0.2-2.1.
Debian
CVE-2020-8024: hylafax - A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of op...
vendor_debian·2020·CVSS 5.3
CVE-2020-8024 [MEDIUM] CVE-2020-8024: hylafax - A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of op...
A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local attackers to escalate from user uucp to users calling hylafax binaries. This issue affects: openSUSE Leap 15.2 hylafax+ versions prior to 7.0.2-lp152.2.1. openSUSE Leap 15.1 hylafax+ version 5.6.1-lp151.3.7 and prior versions. openSUSE Factory hylafax+ versions prior to 7.0.2-2.1.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-29
Published