CVE

Id
3838  
CVE No.
CVE-2001-1034  
Status
Candidate  
Description
Format string vulnerability in Hylafax on FreeBSD allows local users to execute arbitrary code via format specifiers in the -h hostname argument for (1) faxrm or (2) faxalter.  
Phase
Proposed (20020131)  
Votes
ACCEPT(2) Frech, Green | NOOP(4) Christey, Cole, Foat, Wall  
Comments
Christey> Acknowledged in: | BUGTRAQ:20020729 HylaFAX - Various Vulnerabilities Fixed | URL:http://archives.neohapsis.com/archives/bugtraq/2002-07/0358.html | Vendor says problem affects all versions "prior to 4.1.3" | Christey> Confirmed by vendor: | BUGTRAQ:20020729 HylaFAX - Various Vulnerabilities Fixed | URL:http://archives.neohapsis.com/archives/bugtraq/2002-07/0358.html | | Also affects OSes other than FreeBSD. | DEBIAN:DSA-148 | URL:http://www.debian.org/security/2002/dsa-148 | Christey> MANDRAKE:MDKSA-2002:055