First published: Tue Sep 27 2005(Updated: )
xferfaxstats in HylaFax 4.2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the xferfax$$ temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hylafax+ | =4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3069 is considered a medium severity vulnerability due to its potential for local users to exploit file overwrites.
To fix CVE-2005-3069, users should upgrade to a later version of HylaFax that is not affected by this vulnerability.
CVE-2005-3069 affects local users on systems running HylaFax versions up to and including 4.2.1.
CVE-2005-3069 involves a symlink attack which allows file overwriting through manipulation of temporary files.
No, CVE-2005-3069 is a local vulnerability that requires local user access to exploit.