PT-2018-1575 · Mgetty+2 · Mgetty+2
Eric Sesterhenn
·
Published
2018-09-13
·
Updated
2024-08-14
·
CVE-2018-16745
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
mgetty versions prior to 1.2.1
Description
An issue in the fax notify mail function in faxrec.c allows for a buffer overflow due to the
mail to parameter not being sanitized. This could potentially lead to a denial of service if long untrusted input reaches it. The exploitation of this issue may cause a stack-based buffer overflow, allowing an attacker to disrupt service using the mail to parameter.Recommendations
For versions prior to 1.2.1, update to version 1.2.1 or later to resolve the issue. As a temporary workaround, consider restricting input to the
fax notify mail function to prevent long untrusted input from reaching the mail to parameter.Exploit
Fix
Stack Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Suse
Mgetty