vendor:
ActFax Server 5.01 RAW Server
by:
Craig Freyman @cd1zz, corelanc0d3r
N/A
CVSS
N/A
Buffer Overflow
CWE
Product Name: ActFax Server 5.01 RAW Server
Affected Version From: ActFax 5.01
Affected Version To: ActFax 5.01
Patch Exists: YES
Related CWE:
CPE:
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2013
ActFax 5.01 RAW Server Buffer Overflow
This module exploits a vulnerability in ActFax Server 5.01 RAW server. The RAW Server can be used to transfer fax messages to the fax server without any underlying protocols. To note significant fields in the fax being transfered, like fax number and receipient, you can use ActFax data fields. @F506,@F605, and @F000 are all data fields that are vulnerable. For more information refer to the 'data fields' section of the help menu in ActFax. This has been fixed in a beta version which wont be pushed to release until May 2013.
Mitigation:
Beta version of ActFax is available for download which fixes this vulnerability.