First published: Wed Sep 06 2006(Updated: )
c2faxrecv in capi4hylafax 01.02.03 allows remote attackers to execute arbitrary commands via null (\0) and shell metacharacters in the TSI string, as demonstrated by a fax from an anonymous number.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hylafax+ | =01.02.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3126 is considered a critical vulnerability due to its potential for remote code execution.
To fix CVE-2006-3126, upgrade to a newer version of capi4hylafax that mitigates this vulnerability.
CVE-2006-3126 affects capi4hylafax version 01.02.03.
Yes, CVE-2006-3126 allows remote attackers to execute arbitrary commands, potentially leading to unauthorized access.
CVE-2006-3126 can be exploited to execute arbitrary commands via specially crafted TSI strings.