Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE: Security Advisory 2020:1438-1 for Hylafax+ Vulnerability

opensuse
Calendar Grey September 18, 2020
Dist Opensuse Esm H88
This latest openSUSE patch for hylafax+ resolves critical vulnerabilities, including improper directory permissions and errors in file retrieval processes.
An update that fixes two vulnerabilities is now available.

Description

This update for hylafax+ fixes the following issues:

Hylafax was updated to upstream version 7.0.3.

Security issues fixed:

- CVE-2020-15396: Secure temporary directory creation for faxsetup,

faxaddmodem, and probemodem (boo#1173521).

- CVE-2020-15397: Sourcing of files into binaries from user writeable

directories (boo#1173519).

Non-security issues fixed:

* add UseSSLFax feature in sendfax, sendfax.conf, hyla.conf, and

JobControl (31 Jul 2020)

* be more resilient in listening for the Phase C carrier (30 Jul 2020)

* make sure to return to command mode if HDLC receive times out (29 Jul

2020)

* make faxmail ignore boundaries on parts other than multiparts (29 Jul

2020)

* don't attempt to write zero bytes of data to a TIFF (29 Jul 2020)

* don't ever respond to CRP with CRP (28 Jul 2020)

* reset frame counter when a sender retransmits PPS for a previously

confirmed ECM block (26 Jul 2020)

* scrutinize PPM before...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP2:

zypper in -t patch openSUSE-2020-1438=1

Package List

- openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64):

hylafax+-7.0.3-bp152.3.4.1

hylafax+-client-7.0.3-bp152.3.4.1

libfaxutil7_0_3-7.0.3-bp152.3.4.1

References

https://www.suse.com/security/cve/CVE-2020-15396.html

https://www.suse.com/security/cve/CVE-2020-15397.html

https://bugzilla.suse.com/1173519

https://bugzilla.suse.com/1173521

--

Announcement ID: openSUSE-SU-2020:1438-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here