PT-2005-3900 · Hylafax · Hylafax

Javier Fernández-Sanguino Peña

·

Publicado

2005-09-27

·

Atualizado

2008-09-05

·

CVE-2005-3070

CVSS v2.0

3.6

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions HylaFax versions 4.2.1 and earlier
Description The issue allows local users to potentially read faxes and cause a denial of service by creating a UNIX domain socket using the hyla.unix temporary file, as the software does not properly create or verify ownership of this socket.
Recommendations For HylaFax versions 4.2.1 and earlier, consider restricting access to the hyla.unix temporary file to prevent unauthorized creation of the UNIX domain socket until a proper fix is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3070

Produtos afetados

Hylafax