|
Brought to you by:
Suppliers of:
|
|
|
| |
HylaFAX is "a mature (est. 1991) enterprise-class open source software package for sending and receiving facsimiles as well as for sending alpha-numeric pages. It runs on a wide variety of UNIX-like platforms including Linux, BSD (including Mac OS X), SunOS and Solaris, SCO, IRIX, AIX, and HP-UX".
The SuSE Security Team recently audited the HylaFAX daemon (hfaxd) and discovered a remotely exploitable format string vulnerability.
A vulnerable host must have set the 0x002 bit for the ServerTracing configuration parameter. This is not the default setting for the HylaFAX installation, but it is not an uncommon configuration when troubleshooting HylaFAX operation. |
| |
Credit:
The information has been provided by Lee Howard.
|
| |
Vulnerable systems:
* HylaFAX version 4.1.7 and prior
Immune systems:
* HylaFAX version 4.1.8
Solution:
HylaFAX development has released the 4.1.8 patch-level code release which includes the fix for this format string vulnerability as contributed by SuSE. All users are strongly encouraged to upgrade.
Availability:
HylaFAX 4.1.8 is available by anonymous ftp at: ftp://ftp.hylafax.org/source/hylafax-4.1.8.tar.gz.
(Binary versions will shortly be made available)
The fix is available in patch form at: http://bugs.hylafax.org/bugzilla/show_bug.cgi?id=468.
There is no known exploitation in the wild of this vulnerability.
|
|
|
|
|