Mandrake Linux Security Advisory : hylafax (MDKSA-2002:055)

high Nessus Plugin ID 13957

Synopsis

The remote Mandrake Linux host is missing one or more security updates.

Description

Numerous vulnerabilities in the HylaFAX product exist in versions prior to 4.1.3. It does not check the TSI string which is received from remote FAX systems before using it in logging and other places. A remote sender using a specially formatted TSI string can cause the faxgetty program to segfault, resulting in a denial of service. Format string vulnerabilities were also discovered by Christer Oberg, which exist in a number of utilities bundled with HylaFax, such as faxrm, faxalter, faxstat, sendfax, sendpage, and faxwatch. If any of these tools are setuid, they could be used to elevate system privileges.
Mandrake Linux does not, by default, install these tools setuid.
Finally, Lee Howard discovered that faxgetty would segfault due to a buffer overflow after receiving a very large line of image data. This vulnerability could conceivably be used to execute arbitrary commands on the system as root, and could also be exploited more easily as a denial of sevice.

Solution

Update the affected packages.

See Also

https://www.securityfocus.com/archive/1/215984

Plugin Details

Severity: High

ID: 13957

File Name: mandrake_MDKSA-2002-055.nasl

Version: 1.21

Type: local

Published: 7/31/2004

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:hylafax, p-cpe:/a:mandriva:linux:hylafax-client, cpe:/o:mandrakesoft:mandrake_linux:7.1, cpe:/o:mandrakesoft:mandrake_linux:7.2, cpe:/o:mandrakesoft:mandrake_linux:8.2, cpe:/o:mandrakesoft:mandrake_linux:8.1, cpe:/o:mandrakesoft:mandrake_linux:8.0, p-cpe:/a:mandriva:linux:libhylafax4.1.1-devel, p-cpe:/a:mandriva:linux:hylafax-server, p-cpe:/a:mandriva:linux:libhylafax4.1.1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/28/2002

Reference Information

CVE: CVE-2001-1034, CVE-2002-1049, CVE-2002-1050

BID: 3357

MDKSA: 2002:055