PT-2006-4022 · Hylafax · Capi4Hylafax
Lionel Elie Mamane
·
Publicado
2006-09-06
·
Atualizado
2011-03-08
·
CVE-2006-3126
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
capi4hylafax version 01.02.03
Description
The issue allows remote attackers to execute arbitrary commands via null and shell metacharacters in the TSI string. This can be demonstrated by a fax from an anonymous number, which can include malicious input to exploit the weakness.
Recommendations
For capi4hylafax version 01.02.03, consider restricting or validating input for the TSI string to prevent the inclusion of null and shell metacharacters, which can be used to execute arbitrary commands. As a temporary workaround, restrict access to the c2faxrecv function until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Capi4Hylafax