CVE-2005-3539

NameCVE-2005-3539
DescriptionMultiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-933-1
Debian Bugs347298

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
hylafax (PTS)buster3:6.0.6-8.1fixed
bookworm, bullseye, sid3:6.0.7-3.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
hylafaxsourcewoody4.1.1-4woody1DSA-933-1
hylafaxsourcesarge1:4.2.1-5sarge3DSA-933-1
hylafaxsource(unstable)2:4.2.4-2347298

Notes

First patch had regressions

Search for package or bug name: Reporting problems