CVE Vulnerabilities

CVE-2016-2363

Published: Jun 20, 2016 | Modified: Jun 21, 2016
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 uses weak permissions for the /var/www/rpc/surun script, which allows local users to obtain root access for unspecified command execution by leveraging access to the nobody account.

Affected Software

Name Vendor Start Version End Version
Fonality Fonality 12.6 (including) 12.6 (including)
Fonality Fonality 12.8 (including) 12.8 (including)
Fonality Fonality 14.1i (including) 14.1i (including)

References