VulnerabilityModified
CVE-2005-3070
HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the socket using the hyla.unix temporary file.
LOW 3.6EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the socket using the hyla.unix temporary file.
- CVSS 2.0
- 3.6 LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Affected
- hylafax/hylafax
- Source
- cve@mitre.org
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=329384Vendor Advisory
- http://secunia.com/advisories/17107
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:177Vendor Advisory
- http://www.securityfocus.com/bid/15043
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=329384Vendor Advisory
- http://secunia.com/advisories/17107
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:177Vendor Advisory
- http://www.securityfocus.com/bid/15043
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.