efax 0.9 and earlier, when installed setuid root, allows local users to read arbitrary files via the -d option, which prints the contents of the file in a warning message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Efax | Efax | 0.8a (including) | 0.8a (including) |
Efax | Efax | 0.9 (including) | 0.9 (including) |
Efax | Efax | 0.9a (including) | 0.9a (including) |