Vulnerabilities > CVE-2005-3069 - Unspecified vulnerability in Hylafax 4.2.1

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
local
low complexity
hylafax
nessus

Summary

xferfaxstats in HylaFax 4.2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the xferfax$$ temporary file.

Vulnerable Configurations

Part Description Count
Application
Hylafax
1

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-865.NASL
    descriptionJavier Fernandez-Sanguino Pena discovered that several scripts of the hylafax suite, a flexible client/server fax software, create temporary files and directories in an insecure fashion, leaving them vulnerable to symlink exploits.
    last seen2020-06-01
    modified2020-06-02
    plugin id20020
    published2005-10-19
    reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/20020
    titleDebian DSA-865-1 : hylafax - insecure temporary files
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200509-21.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200509-21 (Hylafax: Insecure temporary file creation in xferfaxstats script) Javier Fernandez-Sanguino has discovered that xferfaxstats cron script supplied by Hylafax insecurely creates temporary files with predictable filenames. Impact : A local attacker could create symbolic links in the temporary file directory, pointing to a valid file somewhere on the filesystem. When the xferfaxstats script of Hylafax is executed, this would result in the file being overwritten with the rights of the user running the script, which typically is the root user. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id19820
    published2005-10-05
    reporterThis script is Copyright (C) 2005-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/19820
    titleGLSA-200509-21 : Hylafax: Insecure temporary file creation in xferfaxstats script
  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2005-177.NASL
    descriptionfaxcron, recvstats, and xferfaxstats in HylaFax 4.2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files. (CVE-2005-3069) In addition, HylaFax has some provisional support for Unix domain sockets, which is disabled in the default compile configuration. It is suspected that a local user could create a fake /tmp/hyla.unix socket and intercept fax traffic via this socket. In testing for this vulnerability, with CONFIG_UNIXTRANSPORT disabled, it has been found that client programs correctly exit before sending any data. (CVE-2005-3070) The updated packages have been patched to correct these issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id19985
    published2005-10-11
    reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/19985
    titleMandrake Linux Security Advisory : hylafax (MDKSA-2005:177)