CVE-2005-3070 Affecting hylafax package, versions <1:4.2.2+rc1


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
0.04% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-HYLAFAX-315649
  • published27 Sept 2005
  • disclosed27 Sept 2005

Introduced: 27 Sep 2005

CVE-2005-3070  (opens in a new tab)

How to fix?

Upgrade Debian:unstable hylafax to version 1:4.2.2+rc1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream hylafax package and not the hylafax package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the socket using the hyla.unix temporary file.

CVSS Scores

version 3.1