CVE Vulnerabilities

CVE-2005-3539

Published: Dec 31, 2005 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.

Affected Software

Name Vendor Start Version End Version
Hylafax Hylafax 4.1.1 (including) 4.1.1 (including)
Hylafax Hylafax 4.2 (including) 4.2 (including)
Hylafax Hylafax 4.2.1 (including) 4.2.1 (including)
Hylafax Hylafax 4.2.2 (including) 4.2.2 (including)
Hylafax Hylafax 4.2.3 (including) 4.2.3 (including)
Hylafax Ubuntu dapper *
Hylafax Ubuntu devel *
Hylafax Ubuntu edgy *
Hylafax Ubuntu feisty *

References