c2faxrecv in capi4hylafax 01.02.03 allows remote attackers to execute arbitrary commands via null (0) and shell metacharacters in the TSI string, as demonstrated by a fax from an anonymous number.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Capi4hylafax | Julian_pawlowski | 01.02.03 (including) | 01.02.03 (including) |
Capi4hylafax | Ubuntu | dapper | * |
Capi4hylafax | Ubuntu | devel | * |
Capi4hylafax | Ubuntu | edgy | * |
Capi4hylafax | Ubuntu | feisty | * |
Capi4hylafax | Ubuntu | gutsy | * |
Capi4hylafax | Ubuntu | hardy | * |
Capi4hylafax | Ubuntu | intrepid | * |
Capi4hylafax | Ubuntu | jaunty | * |
Capi4hylafax | Ubuntu | karmic | * |