CVE-2005-3070
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/09/2005
Last modified:
03/04/2025
Description
HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the socket using the hyla.unix temporary file.
Impact
Base Score 2.0
3.60
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:hylafax:hylafax:*:*:*:*:*:*:*:* | 4.2.1 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=329384
- http://secunia.com/advisories/17107
- http://www.mandriva.com/security/advisories?name=MDKSA-2005%3A177
- http://www.securityfocus.com/bid/15043
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=329384
- http://secunia.com/advisories/17107
- http://www.mandriva.com/security/advisories?name=MDKSA-2005%3A177
- http://www.securityfocus.com/bid/15043