Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Debian Hylafax Buffer Overflow Advisory - DSA 148-1 Critical Remote Threat

debian
Calendar Grey August 12, 2002
Debian Logo
Update Hylafax modules to address critical buffer overflow weaknesses and enhance comprehensive security protocols.
A set of problems have been discovered in Hylafax that could allow for a denial of service or possibly the execution of arbitrary code with root privileges.

Summary

A set of problems have been discovered in Hylafax, a flexible
client/server fax software distributed with many GNU/Linux
distributions. Quoting SecurityFocus the problems are in detail:

* A format string vulnerability makes it possible for users to
potentially execute arbitrary code on some implementations. Due to
insufficient checking of input, it's possible to execute a format
string attack. Since this only affects systems with the faxrm and
faxalter programs installed setuid, Debian is not vulnerable.

* A buffer overflow has been reported in Hylafax. A malicious fax
transmission may include a long scan line that will overflow a
memory buffer, corrupting adjacent memory. An exploid may result
in a denial of service condition, or possibly the execution of
arbitrary code with root privileges.

* A format string vulnerability has been discovered in faxgetty.
Incoming fax messages include a Transmitting Subscriber
Identification (TSI) string, used to identify the...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: hylafax

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here