PT-2005-3900 · Hylafax · Hylafax
Javier Fernández-Sanguino Peña
·
Publicado
2005-09-27
·
Atualizado
2008-09-05
·
CVE-2005-3070
CVSS v2.0
3.6
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
HylaFax versions 4.2.1 and earlier
Description
The issue allows local users to potentially read faxes and cause a denial of service by creating a UNIX domain socket using the hyla.unix temporary file, as the software does not properly create or verify ownership of this socket.
Recommendations
For HylaFax versions 4.2.1 and earlier, consider restricting access to the hyla.unix temporary file to prevent unauthorized creation of the UNIX domain socket until a proper fix is applied.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Hylafax