First published: Tue Mar 14 2006(Updated: )
CAPI4HylaFAX 1.3, when compiled with GENERATE_DEBUGSFFDATAFILE set, allows local users to modify arbitrary files via a symlink attack on the c2faxrecv_dbgdatafile.sff temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hylafax+ | =1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1231 is considered a moderate vulnerability that allows local users to perform a symlink attack.
To mitigate CVE-2006-1231, ensure that the GENERATE_DEBUGSFFDATAFILE option is disabled when compiling CAPI4HylaFAX.
CVE-2006-1231 affects local users of CAPI4HylaFAX version 1.3 when compiled with specific options.
CVE-2006-1231 involves a symlink attack which allows unauthorized file modification.
CVE-2006-1231 cannot be exploited remotely as it specifically targets local users.