CVE Vulnerabilities

CVE-2016-2363

Published: Jun 20, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 uses weak permissions for the /var/www/rpc/surun script, which allows local users to obtain root access for unspecified command execution by leveraging access to the nobody account.

Affected Software

NameVendorStart VersionEnd Version
FonalityFonality12.6 (including)12.6 (including)
FonalityFonality12.8 (including)12.8 (including)
FonalityFonality14.1i (including)14.1i (including)

References