MGASA-2018-0456 - Updated hylafax+ packages fix security vulnerability

Publication date: 17 Nov 2018
URL: https://advisories.mageia.org/MGASA-2018-0456.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2018-17141

Luis Merino, Markus Vervier and Eric Sesterhenn discovered that missing
input sanitising in the Hylafax fax software could potentially result in
the execution of arbitrary code via a malformed fax message
(CVE-2018-17141).

References:
- https://bugs.mageia.org/show_bug.cgi?id=23661
- https://www.debian.org/security/2018/dsa-4298
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17141

SRPMS:
- 6/core/hylafax+-5.6.1-1.mga6

Mageia 2018-0456: hylafax+ security update

Luis Merino, Markus Vervier and Eric Sesterhenn discovered that missing input sanitising in the Hylafax fax software could potentially result in the execution of arbitrary code via...

Summary

Luis Merino, Markus Vervier and Eric Sesterhenn discovered that missing input sanitising in the Hylafax fax software could potentially result in the execution of arbitrary code via a malformed fax message (CVE-2018-17141).

References

- https://bugs.mageia.org/show_bug.cgi?id=23661

- https://www.debian.org/security/2018/dsa-4298

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17141

Resolution

MGASA-2018-0456 - Updated hylafax+ packages fix security vulnerability

SRPMS

- 6/core/hylafax+-5.6.1-1.mga6

Severity
Publication date: 17 Nov 2018
URL: https://advisories.mageia.org/MGASA-2018-0456.html
Type: security
CVE: CVE-2018-17141

Related News