Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 6 MGASA-2018-0456 Critical: Hylafax+ Input Sanitization Flaw

mageia
Calendar Grey November 17, 2018
Dist Mageia Esm H88
Hylafax+ patch resolves vulnerabilities linked to command execution threats arising from inadequate input validation as detailed in advisory MGASA-2018-0456 for Mageia 6.
Luis Merino, Markus Vervier and Eric Sesterhenn discovered that missing input sanitising in the Hylafax fax software could potentially result in the execution of arbitrary code via...

Summary

Luis Merino, Markus Vervier and Eric Sesterhenn discovered that missing input sanitising in the Hylafax fax software could potentially result in the execution of arbitrary code via a malformed fax message (CVE-2018-17141).

References

- https://bugs.mageia.org/show_bug.cgi?id=23661

- https://lists.debian.org/debian-security-announce/2018/msg00229.html

- https://www.cve.org/CVERecord?id=CVE-2018-17141

Resolution

SRPMS

- 6/core/hylafax+-5.6.1-1.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 17 Nov 2018
URL: https://advisories.mageia.org/MGASA-2018-0456.html
Type: security
CVE: CVE-2018-17141

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here