Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 uses weak permissions for the /var/www/rpc/surun script, which allows local users to obtain root access for unspecified command execution by leveraging access to the nobody account.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fonality | Fonality | 12.6 (including) | 12.6 (including) |
Fonality | Fonality | 12.8 (including) | 12.8 (including) |
Fonality | Fonality | 14.1i (including) | 14.1i (including) |