CVE-2019-9971 Information
Jun 11, 2022
cve
Description
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tcpdump command without a password. This occurs because the -z (aka postrotate-command) option to tcpdump can be unsafe when used in conjunction with sudo.
Reference
https://www.gosecure.net/blog/2022/05/31/security-advisory-multiple-vulnerabilities-impact-3cx-phone-system/ https://www.securusglobal.com/community/2014/03/17/how-i-got-root-with-sudo/ https://www.gosecure.net/blog
Share on: