HylaFAX Insecure UNIX Domain Socket Usage Vulnerability
BID:15043
Info
HylaFAX Insecure UNIX Domain Socket Usage Vulnerability
| Bugtraq ID: | 15043 |
| Class: | Design Error |
| CVE: |
CVE-2005-3070 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 07 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Javier Fernandez-Sanguino Pena is credited with the discovery of this vulnerability. |
| Vulnerable: |
Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 Hylafax Hylafax 4.2.1 |
| Not Vulnerable: | |
Discussion
HylaFAX Insecure UNIX Domain Socket Usage Vulnerability
HylaFAX is susceptible to a local insecure UNIX domain socket usage vulnerability. This issue is due to a failure of the application to securely implement UNIX domain network communication.
Attackers may gain access to the contents of fax messages containing potentially sensitive information, or deny fax services to legitimate users. Other attacks may also be possible.
HylaFAX is susceptible to a local insecure UNIX domain socket usage vulnerability. This issue is due to a failure of the application to securely implement UNIX domain network communication.
Attackers may gain access to the contents of fax messages containing potentially sensitive information, or deny fax services to legitimate users. Other attacks may also be possible.
Exploit / POC
HylaFAX Insecure UNIX Domain Socket Usage Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
HylaFAX Insecure UNIX Domain Socket Usage Vulnerability
Solution:
Mandrive has released advisory MDKSA-2005:177, along with fixes to address this issue. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Hylafax Hylafax 4.2.1
Solution:
Mandrive has released advisory MDKSA-2005:177, along with fixes to address this issue. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Hylafax Hylafax 4.2.1
-
Mandriva hylafax-4.2.1-2.1.20060mdk.i586.rpm
Mandrivalinux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva hylafax-4.2.1-2.1.20060mdk.x86_64.rpm
Mandrivalinux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva hylafax-client-4.2.1-2.1.20060mdk.i586.rpm
Mandrivalinux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva hylafax-client-4.2.1-2.1.20060mdk.x86_64.rpm
Mandrivalinux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva hylafax-server-4.2.1-2.1.20060mdk.i586.rpm
Mandrivalinux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva hylafax-server-4.2.1-2.1.20060mdk.x86_64.rpm
Mandrivalinux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva lib64hylafax4.2.0-4.2.1-2.1.20060mdk.x86_64.rpm
Mandrivalinux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva lib64hylafax4.2.0-devel-4.2.1-2.1.20060mdk.x86_64.rpm
Mandrivalinux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva libhylafax4.2.0-4.2.1-2.1.20060mdk.i586.rpm
Mandrivalinux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva libhylafax4.2.0-devel-4.2.1-2.1.20060mdk.i586.rpm
Mandrivalinux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3
References
HylaFAX Insecure UNIX Domain Socket Usage Vulnerability
References:
References: