Description
c2faxrecv in capi4hylafax 01.02.03 allows remote attackers to execute arbitrary commands via null (\0) and shell metacharacters in the TSI string, as demonstrated by a fax from an anonymous number.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1165-1 | New capi4hylafax packages fix arbitrary command execution |
EUVD |
EUVD-2006-3123 | c2faxrecv in capi4hylafax 01.02.03 allows remote attackers to execute arbitrary commands via null (\0) and shell metacharacters in the TSI string, as demonstrated by a fax from an anonymous number. |
References
History
No history.
Status: PUBLISHED
Assigner: debian
Published:
Updated: 2024-08-07T18:16:05.933Z
Reserved: 2006-06-21T00:00:00.000Z
Link: CVE-2006-3126
No data.
Status : Modified
Published: 2006-09-06T00:04:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2006-3126
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD