EFax UUCP-style Lock File Command Line Option Buffer Overflow Vulnerability

BID:3894

Info

EFax UUCP-style Lock File Command Line Option Buffer Overflow Vulnerability

Bugtraq ID: 3894
Class: Boundary Condition Error
CVE: CVE-2002-0130
Remote: No
Local: Yes
Published: Jan 16 2002 12:00AM
Updated: Jul 11 2009 09:56AM
Credit: This vulnerability was submitted to BugTraq on January 16th, 2002 by "Wodahs Latigid" <[email protected]>.
Vulnerable: efax efax 0.9 a
efax efax 0.9
+ Mandriva Linux Mandrake 8.1
+ Redhat Linux 7.2
+ Redhat Linux 7.1
+ Redhat Linux 7.0
efax efax 0.8 a
- Redhat Linux 6.0
- Turbolinux Turbolinux 6.0
Not Vulnerable:

Discussion

EFax UUCP-style Lock File Command Line Option Buffer Overflow Vulnerability

efax is an easy-to-use fax utility that ships with a number of Linux distributions. efax also ships with the KDE desktop.

efax does not perform proper bounds checking on command line options. In particular, the buffer for the -x switch can be overrun, causing memory to be overwritten. As a result the attacker may be able to overwrite stack variables, such as the return address, to cause attacker-supplied instructions to be executed.

efax is not installed setuid root in most circumstances. However, it may be installed setuid root when built from scratch by a user. This is known to be the case with the version of efax that ships with the kde-2.2.1 source build and install as part of the klprfax app in the kdeutils package. The issue of efax being installed setuid root has apparently been remedied in the kde-2.2.2 source build. This does not discount the possibility of other instances where efax is installed with setuid root privileges.

In the case that efax is installed setuid root, this vulnerability may allow a local attacker to escalate their privileges to that of the root user.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report