PT-2006-4022 · Hylafax · Capi4Hylafax
Lionel Elie Mamane
·
Published
2006-09-06
·
Updated
2011-03-08
·
CVE-2006-3126
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
capi4hylafax version 01.02.03
Description
The issue allows remote attackers to execute arbitrary commands via null and shell metacharacters in the TSI string. This can be demonstrated by a fax from an anonymous number, which can include malicious input to exploit the weakness.
Recommendations
For capi4hylafax version 01.02.03, consider restricting or validating input for the TSI string to prevent the inclusion of null and shell metacharacters, which can be used to execute arbitrary commands. As a temporary workaround, restrict access to the c2faxrecv function until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Capi4Hylafax