SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-3070

HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the socket using the hyla.unix temporary file.

LOW 3.6EPSS 0.36%

Does this matter?

Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.

Description

HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the socket using the hyla.unix temporary file.

CVSS 2.0
3.6 LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
EPSS
0.36% probability · 30th percentile
CISA KEV
Not listed
Affected
hylafax/hylafax
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.