Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 uses weak permissions for the /var/www/rpc/surun script, which allows local users to obtain root access for unspecified command execution by leveraging access to the nobody account.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Fonality | Fonality | 12.6 (including) | 12.6 (including) |
| Fonality | Fonality | 12.8 (including) | 12.8 (including) |
| Fonality | Fonality | 14.1i (including) | 14.1i (including) |