PT-2006-4022 · Hylafax · Capi4Hylafax

Lionel Elie Mamane

·

Published

2006-09-06

·

Updated

2011-03-08

·

CVE-2006-3126

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions capi4hylafax version 01.02.03
Description The issue allows remote attackers to execute arbitrary commands via null and shell metacharacters in the TSI string. This can be demonstrated by a fax from an anonymous number, which can include malicious input to exploit the weakness.
Recommendations For capi4hylafax version 01.02.03, consider restricting or validating input for the TSI string to prevent the inclusion of null and shell metacharacters, which can be used to execute arbitrary commands. As a temporary workaround, restrict access to the c2faxrecv function until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3126
DSA-1165

Affected Products

Capi4Hylafax