CVE Vulnerabilities

CVE-2004-1182

Published: Dec 31, 2004 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

hfaxd in HylaFAX before 4.2.1, when installed with a weak hosts.hfaxd file, allows remote attackers to authenticate and bypass intended access restrictions via a crafted (1) username or (2) hostname that satisfies a regular expression that is matched against a hosts.hfaxd entry without a password.

Affected Software

Name Vendor Start Version End Version
Hylafax Hylafax 4.1.1 4.1.1
Hylafax Hylafax 4.1.2 4.1.2
Hylafax Hylafax 4.1.3 4.1.3
Hylafax Hylafax 4.1.5 4.1.5
Hylafax Hylafax 4.1.6 4.1.6
Hylafax Hylafax 4.1.7 4.1.7
Hylafax Hylafax 4.1.8 4.1.8
Hylafax Hylafax 4.1_beta1 4.1_beta1
Hylafax Hylafax 4.1_beta2 4.1_beta2
Hylafax Hylafax 4.1_beta3 4.1_beta3
Hylafax Hylafax 4.2.0 4.2.0
Hylafax Ubuntu dapper *
Hylafax Ubuntu devel *
Hylafax Ubuntu edgy *
Hylafax Ubuntu feisty *

References