CVE-2005-3539

NameCVE-2005-3539
DescriptionMultiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-933-1
Debian Bugs347298

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
hylafax (PTS)buster3:6.0.6-8.1fixed
bullseye3:6.0.7-3.1fixed
bookworm3:6.0.7-5fixed
trixie3:6.0.7-7fixed
sid3:6.0.7-9fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
hylafaxsourcewoody4.1.1-4woody1DSA-933-1
hylafaxsourcesarge1:4.2.1-5sarge3DSA-933-1
hylafaxsource(unstable)2:4.2.4-2347298

Notes

First patch had regressions

Search for package or bug name: Reporting problems