Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that contains security fixes can now be installed. . openSUSE Security Update: Security update for hylafax+ ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1494-1 Rating: moderate References: #1191571 Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: hylafax+ was updated to version 7.0.4: * README.SUSE renamed * hylafax.diff added for boo#1191571 (pre-correction) * Dependencies on systemd-services adjusted * retry training twice at the same bitrate unless FTT (26 Aug 2021) * add missing reason messages for session failures (21 Aug 2021) * stop attempts to send or receive signals if the call ended prematurely (16-19 Aug 2021) * add Class1HasRMHookIndication (16 Aug 2021) * don't attempt sending DCN if we're already on hook (15, 17 Aug 2021) * end session sooner if receiver hangs up immediately after TCF or during prologue (14 Aug 2021) * fix some behavior following frame reception timeouts (13 Aug 2021) * improve behavior if procedural interrupt fails (12 Aug 2021) * handle sender repeating RR after we transmit MCF (10 Aug 2021) * add session logging of receipt of CFR/FTT signals (3 Aug 2021) * cope with receipt of PPR following CTC (3 Aug 2021) * attempt to cope with NSF/CSI/DIS after PPS, CTR, ERR, RR and improve coping with the same after MPS/EOP/EOM (2, 12, 14, 18 Aug 2021) * identify DCN after PPS as a receiver abort (2 Aug 2021) * attempt to cope with receipt of CTR after sending PPS (2 Aug 2021) * remove use of deprecated libtiff integer types and "register" storage class specifier (25 Jul 2021) * don't employ senderFumblesECM if V.34-Fax was negotiated (25 Jul 2021) * update configure to accept libtiff v4.2 and v4.3 (24 Jul 2021) * fix pagehandling "botch" if a job's first and previous attempts were on a proxy (20 Jul 2021) * fix data timeout for bitrates less than 14400 bps when non-zero scanline time (15 Jul 2021) * try to cope with T.38 invite stutter at beginning of send (15 Jul 2021) * decouple session logging from direct filesystem I/O (15 Jul 2021) * try to help receivers who may expect initial 1-bits to start high-speed data (8, 9 Jul, 4 Aug 2021) * improve tenacity of "persistent" ECM (26 Jun 2021) * maintain the same SSL Fax passcode during a single session (20 May 2021) * log detection of binary file transfer support in receivers (1 Apr 2021) * add support for SiLabs Si2417/Si2435 (5 Feb 2021) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2021-1494=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): hylafax+-7.0.4-bp153.2.3.1 hylafax+-client-7.0.4-bp153.2.3.1 libfaxutil7_0_4-7.0.4-bp153.2.3.1 References: https://bugzilla.suse.com/1191571 . Apply the most recent openSUSE Security Patch for hylafax+ in order to resolve multiple security vulnerabilities and enhancements.. Hylafax Security Patch, Linux Patch Management, openSUSE Update. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for hylafax+ ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1209-1 Rating: moderate References: #1173519 #1173521 Cross-References: CVE-2020-15396 CVE-2020-15397 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for hylafax+ fixes the following issues: Hylafax was updated to upstream version 7.0.3. Security issues fixed: - CVE-2020-15396: Secure temporary directory creation for faxsetup, faxaddmodem, and probemodem (boo#1173521). - CVE-2020-15397: Sourcing of files into binaries from user writeable directories (boo#1173519). Non-security issues fixed: * add UseSSLFax feature in sendfax, sendfax.conf, hyla.conf, and JobControl (31 Jul 2020) * be more resilient in listening for the Phase C carrier (30 Jul 2020) * make sure to return to command mode if HDLC receive times out (29 Jul 2020) * make faxmail ignore boundaries on parts other than multiparts (29 Jul 2020) * don't attempt to write zero bytes of data to a TIFF (29 Jul 2020) * don't ever respond to CRP with CRP (28 Jul 2020) * reset frame counter when a sender retransmits PPS for a previously confirmed ECM block (26 Jul 2020) * scrutinize PPM before concluding that the sender missed our MCF (23 Jul 2020) * fix modem recovery after SSL Fax failure (22, 26 Jul 2020) * ignore echo of PPR, RTN, CRP (10, 13, 21 Jul 2020) * attempt to handle NSF/CSI/DIS in Class 1 sending Phase D (6 Jul 2020) * run scripts directly rather than invoking them via a shell for security hardening (3-5 Jul 2020) * add senderFumblesECM feature (3 Jul 2020) * add support for PIN/PIP/PRI-Q/PPS-PRI-Q signals, addsenderConfusesPIN feature, and utilize PIN for rare conditions where it may be helpful (2, 6, 13-14 Jul 2020) * add senderConfusesRTN feature (25-26 Jun 2020) * add MissedPageHandling feature (24 Jun 2020) * use and handle CFR in Phase D to retransmit Phase C (16, 23 Jun 2020) * cope with hearing echo of RR, CTC during Class 1 sending (15-17 Jun 2020) * fix listening for retransmission of MPS/EOP/EOM if it was received corrupt on the first attempt (15 Jun 2020) * don't use CRP when receiving PPS/PPM as some senders think we are sending MCF (12 Jun 2020) * add BR_SSLFAX to show SSL Fax in notify and faxinfo output (1 Jun 2020) * have faxinfo put units on non-standard page dimensions (28 May 2020) * improve error messages for JobHost connection errors (22 May 2020) * fix perpetual blocking of jobs when a job preparation fails, attempt to fix similar blocking problems for bad jobs in batches, and add "unblock" faxconfig feature (21 May 2020) * ignore TCF if we're receiving an SSL Fax (31 Jan 2020) * fixes for build on FreeBSD 12.1 (31 Jan - 3 Feb 2020) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-1209=1 Package List: - openSUSE Leap 15.2 (x86_64): hylafax+-7.0.3-lp152.3.6.1 hylafax+-client-7.0.3-lp152.3.6.1 hylafax+-client-debuginfo-7.0.3-lp152.3.6.1 hylafax+-debuginfo-7.0.3-lp152.3.6.1 hylafax+-debugsource-7.0.3-lp152.3.6.1 libfaxutil7_0_3-7.0.3-lp152.3.6.1 libfaxutil7_0_3-debuginfo-7.0.3-lp152.3.6.1 References: https://www.suse.com/security/cve/CVE-2020-15396.html https://www.suse.com/security/cve/CVE-2020-15397.html https://bugzilla.suse.com/1173519 https://bugzilla.suse.com/1173521 -- . openSUSE Security Update: Security update forhylafax+ _____________________________________________. update, security, fixes, vulnerabilities, opensuse. . LinuxSecurity.com Team
Luis Merino, Markus Vervier and Eric Sesterhenn discovered that missing input sanitising in the Hylafax fax software could potentially result in the execution of arbitrary code via a malformed fax message. . Package : hylafax Version : 3:6.0.6-6+deb8u1 CVE ID : CVE-2018-17141 Luis Merino, Markus Vervier and Eric Sesterhenn discovered that missing input sanitising in the Hylafax fax software could potentially result in the execution of arbitrary code via a malformed fax message. For Debian 8 "Jessie", this problem has been fixed in version 3:6.0.6-6+deb8u1. We recommend that you upgrade your hylafax packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A critical security patch for Hylafax addresses a vulnerability in input validation that could allow attackers to execute arbitrary code. Users are urged to upgrade to the latest version.. Hylafax Security Update, Debian LTS, Input Sanitization, Arbitrary Code Execution. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for hylafax+ ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2797-1 Rating: critical References: #1109084 Cross-References: CVE-2018-17141 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for hylafax+ fixes the following issues: Security issues fixed in 5.6.1: - CVE-2018-17141: multiple vulnerabilities affecting fax page reception in JPEG format Specially crafted input may have allowed remote execution of arbitrary code (boo#1109084) Additionally, this update also contains all upstream corrections and bugfixes in the 5.6.1 version, including: - fix RFC2047 encoding by notify - add jobcontrol PageSize feature - don't wait forever after +FRH:3 - fix faxmail transition between a message and external types - avoid pagehandling from introducing some unnecessary EOM signals - improve proxy connection error handling and logging - add initial ModemGroup limits feature - pass the user's uid onto the session log file for sent faxes - improve job waits to minimize triggers - add ProxyTaglineFormat and ProxyTSI features Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-1027=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-1027=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): hylafax+-5.6.1-15.1 hylafax+-client-5.6.1-15.1 hylafax+-client-debuginfo-5.6.1-15.1 hylafax+-debuginfo-5.6.1-15.1 hylafax+-debugsource-5.6.1-15.1 libfaxutil5_6_1-5.6.1-15.1 libfaxutil5_6_1-debuginfo-5.6.1-15.1 - openSUSE Leap 15.0 (x86_64): hylafax+-5.6.1-lp150.5.6.1 hylafax+-client-5.6.1-lp150.5.6.1 hylafax+-client-debuginfo-5.6.1-lp150.5.6.1 hylafax+-debuginfo-5.6.1-lp150.5.6.1 hylafax+-debugsource-5.6.1-lp150.5.6.1 libfaxutil5_6_1-5.6.1-lp150.5.6.1 libfaxutil5_6_1-debuginfo-5.6.1-lp150.5.6.1 References: https://www.suse.com/security/cve/CVE-2018-17141.html https://bugzilla.suse.com/1109084 -- . Important openSUSE patch resolves security vulnerabilities in hylafax+. Find installation instructions here!. openSUSE Security, Hylafax Update, Critical Issues, Software Fixes. . Severity: Critical. LinuxSecurity.com Team
Luis Merino, Markus Vervier and Eric Sesterhenn discovered that missing input sanitising in the Hylafax fax software could potentially result in the execution of arbitrary code via a malformed fax message. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4298-1
Patrice Fournier found that hylafax passes unsanitized user data in the notify script, allowing users with the ability to submit jobs to run arbitrary commands with the privileges of the hylafax server.. - --------------------------------------------------------------------------Debian Security Advisory DSA 933-1
Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 865-1
Hylafax is vulnerable to linking attacks, potentially allowing a local user to overwrite arbitrary files.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200509-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Hylafax: Insecure temporary file creation in xferfaxstats script Date: September 30, 2005 Bugs: #106882 ID: 200509-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Hylafax is vulnerable to linking attacks, potentially allowing a local user to overwrite arbitrary files. Background ========= Hylafax is a client-server fax package for class 1 and 2 fax modems. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/hylafax < 4.2.2 *> = 4.2.0-r3 *> = 4.2.1-r2 > = 4.2.2 Description ========== Javier Fernandez-Sanguino has discovered that xferfaxstats cron script supplied by Hylafax insecurely creates temporary files with predictable filenames. Impact ===== A local attacker could create symbolic links in the temporary file directory, pointing to a valid file somewhere on the filesystem. When the xferfaxstats script of Hylafax is executed, this would result in the file being overwritten with the rights of the user running the script, which typically is the root user. Workaround ========= There is no known workaround at this time. Resolution ========= All Hylafax users should upgrade to the latestversion: # emerge --sync # emerge --ask --oneshot --verbose net-misc/hylafax References ========= [ 1 ] Original bug report Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200509-21 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.