First published: Tue Sep 27 2005(Updated: )
HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the socket using the hyla.unix temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hylafax+ | <=4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3070 is classified as a medium severity vulnerability due to potential local user exploitation.
To fix CVE-2005-3070, upgrade HylaFax to version 4.2.2 or later where ownership of the UNIX domain socket is properly handled.
CVE-2005-3070 affects HylaFax versions 4.2.1 and earlier.
The potential consequences of CVE-2005-3070 include unauthorized access to fax contents and potential denial of service.
CVE-2005-3070 is a local vulnerability that requires an authenticated user to exploit.