|
Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2006:015: hylafax Vulnerability Scan
Vulnerability Scan Summary Check for the version of the hylafax package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2006:015 (hylafax).
Patrice Fournier discovered the faxrcvd/notify scripts (executed as the uucp/
fax user) run user-supplied input through eval without any attempt at
sanitising it first. This would allow any user who could submit jobs to
HylaFAX, or through telco manipulation control the representation of callid
information presented to HylaFAX to run arbitrary commands as the uucp/fax
user. (CVE-2005-3539, only 'notify' in the covered versions) Updated packages
were also reviewed for vulnerability to an issue where if PAM is disabled, a
user could log in with no password. (CVE-2005-3538) In addition, some fixes to
the packages for permissions, and the %pre/%post scripts were backported from
cooker. (#19679) The updated packages have been patched to correct these
issues.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:015
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|