7.5

CVE-2005-3538

hfaxd in HylaFAX 4.2.3, when PAM support is disabled, accepts arbitrary passwords, which allows remote attackers to gain privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ifax SolutionsHylafax Version4.2.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.48% 0.825
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://bugs.hylafax.org/bugzilla/show_bug.cgi?id=719
Patch
http://secunia.com/advisories/18314
Patch
Vendor Advisory
http://secunia.com/advisories/18337
Patch
Vendor Advisory
http://secunia.com/advisories/18489
http://www.gentoo.org/security/en/glsa/glsa-200601-03.xml
Patch
http://www.hylafax.org/archive/2005-12/msg00119.php
http://www.hylafax.org/content/HylaFAX_4.2.4_release
http://www.mandriva.com/security/advisories?name=MDKSA-2006:015
http://www.securityfocus.com/archive/1/420974/100/0/threaded
http://www.securityfocus.com/bid/16150
Patch
http://www.vupen.com/english/advisories/2006/0072