You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa hylafax

Sigurnosni nedostaci programskog paketa hylafax

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2020-01eb48bcce
2020-08-13 01:38:09.349067
——————————————————————————–

Name : hylafax+
Product : Fedora 32
Version : 7.0.3
Release : 1.fc32
URL : http://hylafax.sourceforge.net
Summary : An enterprise-strength fax server
Description :
HylaFAX(tm) is a enterprise-strength fax server supporting
Class 1 and 2 fax modems on UNIX systems. It provides spooling
services and numerous supporting fax management tools.
The fax clients may reside on machines different from the server
and client implementations exist for a number of platforms including
windows.

——————————————————————————–
Update Information:

update to 7.0.3
——————————————————————————–
ChangeLog:

* Tue Aug 4 2020 Lee Howard <faxguy@howardsilvan.com> – 7.0.3-1
– update to 7.0.3
* Tue Jul 28 2020 Fedora Release Engineering <releng@fedoraproject.org> – 7.0.2-2
– Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
——————————————————————————–
References:

[ 1 ] Bug #1852803 – CVE-2020-15397 hylafax+: unsafe handling of user-writable directories could lead to privileged code execution
https://bugzilla.redhat.com/show_bug.cgi?id=1852803
[ 2 ] Bug #1852809 – CVE-2020-15396 hylafax+: race condition in faxsetup utility could lead to privileges escalation
https://bugzilla.redhat.com/show_bug.cgi?id=1852809
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2020-01eb48bcce’ at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

——————————————————————————–
Fedora Update Notification
FEDORA-2020-8aa8793d25
2020-08-13 01:31:05.710853
——————————————————————————–

Name : hylafax+
Product : Fedora 31
Version : 7.0.3
Release : 1.fc31
URL : http://hylafax.sourceforge.net
Summary : An enterprise-strength fax server
Description :
HylaFAX(tm) is a enterprise-strength fax server supporting
Class 1 and 2 fax modems on UNIX systems. It provides spooling
services and numerous supporting fax management tools.
The fax clients may reside on machines different from the server
and client implementations exist for a number of platforms including
windows.

——————————————————————————–
Update Information:

update to 7.0.3
——————————————————————————–
ChangeLog:

* Tue Aug 4 2020 Lee Howard <faxguy@howardsilvan.com> – 7.0.3-1
– update to 7.0.3
* Tue Jul 28 2020 Fedora Release Engineering <releng@fedoraproject.org> – 7.0.2-2
– Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Thu Jan 30 2020 Lee Howard <faxguy@howardsilvan.com> – 7.0.2-1
– update to 7.0.2
* Wed Jan 29 2020 Fedora Release Engineering <releng@fedoraproject.org> – 7.0.1-2
– Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
——————————————————————————–
References:

[ 1 ] Bug #1852803 – CVE-2020-15397 hylafax+: unsafe handling of user-writable directories could lead to privileged code execution
https://bugzilla.redhat.com/show_bug.cgi?id=1852803
[ 2 ] Bug #1852809 – CVE-2020-15396 hylafax+: race condition in faxsetup utility could lead to privileges escalation
https://bugzilla.redhat.com/show_bug.cgi?id=1852809
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2020-8aa8793d25’ at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

AutorFilip Omazic
Cert idNCERT-REF-2020-08-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Nadogradnja za Microsoft Office Online Server

Microsoft je izdao nadogradnju za Microsoft Office Online Server. Pronađene su ranjivosti koje potencijalnim napadačima omogućuju otkrivanje osjetljivih informacija ili...

Close