vendor:
Hylafax
by:
Brock Tellier
7.2
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Hylafax
Affected Version From: Hylafax 4.0.2
Affected Version To: Hylafax 4.0.2
Patch Exists: YES
Related CWE: N/A
CPE: a:hylafax:hylafax
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD 3.3-RELEASE
1999
Hylafax faxalter Buffer Overflow
Hylafax is a popular fax server software package designed to run on multiple UNIX operating systems. Some versions of Hylafax ship with a vulnerable sub program 'faxalter'. This program is installed SUID UUCP and has a buffer overflow which if exploited will allow a malicious user to gain UUCP privileges. Because the important programs are executed as root, such as Minicom (a popular modem terminal program) or cu(1) and are in the UUCP group and therefore writable by the same group they could be trojaned by the attacker.
Mitigation:
Upgrade to the latest version of Hylafax