|
Family: Misc. --> Category: attack
HylaFAX hfaxd Password Check Vulnerability Vulnerability Scan
Vulnerability Scan Summary Checks for password check vulnerability in HylaFAX hfaxd
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote fax server fails to properly validate passwords.
Description :
The remote host is running HylaFAX, a fax / pager server application
for Linux / unix.
The version of HylaFAX installed on the remote host does not check
passwords when authenticating users via hfaxd, its fax server. An
attacker can exploit this issue to bypass authentication using a valid
username and gain access to the system.
See also :
http://bugs.hylafax.org/bugzilla/show_bug.cgi?id=682
http://www.hylafax.org/content/HylaFAX_4.2.4_release
Solution :
Rebuild HylaFAX with PAM support or upgrade to HylaFAX version 4.2.4
or later.
Threat Level:
High / CVSS Base Score : 7.0
(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|