CVE-2005-3539

NameCVE-2005-3539
DescriptionMultiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-933-1
NVD severityhigh (attack range: remote)
Debian Bugs347298

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
hylafax (PTS)wheezy3:6.0.6-5fixed
jessie3:6.0.6-6fixed
stretch3:6.0.6-7fixed
buster, sid3:6.0.6-8fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
hylafaxsource(unstable)2:4.2.4-2high347298
hylafaxsourcesarge1:4.2.1-5sarge3highDSA-933-1
hylafaxsourcewoody4.1.1-4woody1highDSA-933-1

Notes

First patch had regressions

Search for package or bug name: Reporting problems