CVE-2004-1182: High severity hylafax hylafax vulnerability
hfaxd in HylaFAX before 4.2.1, when installed with a "weak" hosts.hfaxd file, allows remote attackers to authenticate and bypass intended access restrictions via a crafted (1) username or (2) hostname that satisfies a regular expression that is matched against a hosts.hfaxd entry without a password.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1182?
CVE-2004-1182 is classified as a medium severity vulnerability related to authentication bypass in HylaFAX.
How do I fix CVE-2004-1182?
To fix CVE-2004-1182, upgrade to HylaFAX version 4.2.1 or later which addresses this vulnerability.
What systems are affected by CVE-2004-1182?
CVE-2004-1182 affects HylaFAX versions prior to 4.2.1 including 4.1.1, 4.1.2, 4.1.3, and other versions up to 4.2.0.
What type of attack can be executed using CVE-2004-1182?
An attacker can exploit CVE-2004-1182 to authenticate and bypass access restrictions by manipulating the username or hostname.
Is there a known exploit for CVE-2004-1182?
Yes, there are known exploit methods for CVE-2004-1182 that allow attackers to gain unauthorized access.