CVE-2002-1049: Medium severity Hylafax HylaFAX vulnerability
Published Oct 4, 2002
·Updated
Format string vulnerability in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service (crash) via the TSI data element.
Affected Software
10 affected components
Hylafax HylaFAX=4.1_beta1
Hylafax HylaFAX=4.1
Hylafax HylaFAX=4.0_pl2
Hylafax HylaFAX=4.0_pl0
Hylafax HylaFAX=4.1.2
Hylafax HylaFAX=4.0_pl1
Hylafax HylaFAX=4.1.1
Hylafax HylaFAX=4.1_beta2
Hylafax HylaFAX=4.0.2
Hylafax HylaFAX=4.1_beta3
Remediation
Patch Available
Patch Available
Patch Available
Event History
Oct 4, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1049?
CVE-2002-1049 has a severity rating of medium due to its potential to cause denial of service.
2
How do I fix CVE-2002-1049?
To fix CVE-2002-1049, upgrade to HylaFAX version 4.1.3 or later.
3
What versions of HylaFAX are affected by CVE-2002-1049?
CVE-2002-1049 affects HylaFAX versions prior to 4.1.3, including versions 4.0.2, 4.0_pl0, 4.0_pl1, 4.0_pl2, and 4.1.
4
What type of vulnerability is CVE-2002-1049?
CVE-2002-1049 is a format string vulnerability that can lead to application crashes.
5
Who can exploit CVE-2002-1049?
CVE-2002-1049 can be exploited by remote attackers who can send specially crafted TSI data elements.