CVE Vulnerabilities

CVE-2006-3126

Published: Sep 06, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

c2faxrecv in capi4hylafax 01.02.03 allows remote attackers to execute arbitrary commands via null (0) and shell metacharacters in the TSI string, as demonstrated by a fax from an anonymous number.

Affected Software

NameVendorStart VersionEnd Version
Capi4hylafaxJulian_pawlowski01.02.03 (including)01.02.03 (including)
Capi4hylafaxUbuntudapper*
Capi4hylafaxUbuntudevel*
Capi4hylafaxUbuntuedgy*
Capi4hylafaxUbuntufeisty*
Capi4hylafaxUbuntugutsy*
Capi4hylafaxUbuntuhardy*
Capi4hylafaxUbuntuintrepid*
Capi4hylafaxUbuntujaunty*
Capi4hylafaxUbuntukarmic*

References