PT-2005-3900 · Hylafax · Hylafax

Javier Fernández-Sanguino Peña

·

Published

2005-09-27

·

Updated

2008-09-05

·

CVE-2005-3070

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions HylaFax versions 4.2.1 and earlier
Description The issue allows local users to potentially read faxes and cause a denial of service by creating a UNIX domain socket using the hyla.unix temporary file, as the software does not properly create or verify ownership of this socket.
Recommendations For HylaFax versions 4.2.1 and earlier, consider restricting access to the hyla.unix temporary file to prevent unauthorized creation of the UNIX domain socket until a proper fix is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3070

Affected Products

Hylafax