Vulnerability Description
Heap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote attackers to cause a denial of service (child hang) or execute arbitrary code via a long USER command.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lee Howard | Hylafax\+ | 5.2.4 |
Related Weaknesses (CWE)
References
- http://hylafax.sourceforge.net/news/5.5.4.phpVendor Advisory
- http://securitytracker.com/id?1029119
- http://www.exploit-db.com/exploits/28683Exploit
- http://www.securityfocus.com/archive/1/528943
- http://www.securityfocus.com/bid/62729
- http://hylafax.sourceforge.net/news/5.5.4.phpVendor Advisory
- http://securitytracker.com/id?1029119
- http://www.exploit-db.com/exploits/28683Exploit
- http://www.securityfocus.com/archive/1/528943
- http://www.securityfocus.com/bid/62729
FAQ
What is CVE-2013-5680?
CVE-2013-5680 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Heap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote attackers to cause a denial of service (child hang) or execute arbitrary code vi...
How severe is CVE-2013-5680?
CVE-2013-5680 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-5680?
Check the references section above for vendor advisories and patch information. Affected products include: Lee Howard Hylafax\+.