HylaFAX: Remote code exploit in hylafax
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200311-03 / HylaFAX |
| Release Date |
November 10, 2003 |
| Latest Revision |
November 10, 2003: 01 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-misc/hylafax |
<=
4.1.7 |
>=
4.1.8 |
All supported architectures
|
Related bugreports:
#33368
Synopsis
A format bug condition allows a remote attacjer to execute arbitrary code as
the root user.
2.
Impact Information
Background
HylaFAX is a popular client-server fax package.
Description
During a code review of the hfaxd server, the SuSE Security Team discovered
a format bug condition that allows a remote attacker to execute arbitrary
code as the root user. However, the bug cannot be triggered in the default
hylafax configuration.
Impact
A remote attacker could execute arbitrary code with root privileges.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
Users are encouraged to perform an 'emerge sync' and upgrade the package to
the latest available version. Vulnerable versions of hylafax have been
removed from portage. Specific steps to upgrade:
Code Listing 3.1: Resolution |
# emerge sync
# emerge -pv '>=net-misc/hylafax-4.1.8'
# emerge '>=net-misc/hylafax-4.1.8'
# emerge clean
|
4.
References
|