Alerts This Week
Warning Icon 1 1,179
Alerts This Week
Warning Icon 1 1,179

Debian: DSA 634-1 Moderate: Hylafax Unauthorized Access Risk

debian
Calendar Grey January 11, 2005
Debian Logo
--------------------------------------------------------------------------Debian Security Advisory D
Patrice Fournier discovered a vulnerability in the authorisation subsystem of hylafax, a flexible client/server fax system

Summary


192.168.0
username:uid:pass:adminpass
user@host

After updating, these entries will need to be modified in order to
continue to function. Respectively, the correct entries should be

192.168.0.[0-9]+
username@:uid:pass:adminpass
user@host

Unless such maching of "username" with "otherusername" and "host" with
"hostname" is desired, the proper form of these entries should include
the delimiter and markers like this

@192.168.0.[0-9]+$
^username@:uid:pass:adminpass
^user@host$

For the stable distribution (woody) this problem has been fixed in
version 4.1.1-3.1.

For the unstable distribution (sid) this problem has been fixed in
version 4.2.1-1.

We recommend that you upgrade your hylafax packages.


Upgrade Instructions
--------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will up...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

--------------------------------------------------------------------------Package: hylafax
CVE ID: CAN-2004-1182

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here