CVE Vulnerabilities

CVE-2016-2363

Published: Jun 20, 2016 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 uses weak permissions for the /var/www/rpc/surun script, which allows local users to obtain root access for unspecified command execution by leveraging access to the nobody account.

Affected Software

Name Vendor Start Version End Version
Fonality Fonality 12.6 (including) 12.6 (including)
Fonality Fonality 12.8 (including) 12.8 (including)
Fonality Fonality 14.1i (including) 14.1i (including)

References