Vulnerability Description
HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit enabled, which is mishandled in FaxModem::writeECMData() in the faxd/CopyQuality.c++ file.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 8.0 |
| Hylafax | Hylafax | 6.0.6 |
| Hylafax | Hylafax\+ | 5.6.0 |
Related Weaknesses (CWE)
References
- http://git.hylafax.org/HylaFAX?a=commit%3Bh=c6cac8d8cd0dbe313689ba77023e12bc5b30
- http://www.openwall.com/lists/oss-security/2018/09/20/1ExploitMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00026.htmlMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2018/Sep/49ExploitMailing ListThird Party Advisory
- https://www.debian.org/security/2018/dsa-4298Third Party Advisory
- https://www.x41-dsec.de/lab/advisories/x41-2018-008-hylafax/ExploitThird Party Advisory
- http://git.hylafax.org/HylaFAX?a=commit%3Bh=c6cac8d8cd0dbe313689ba77023e12bc5b30
- http://www.openwall.com/lists/oss-security/2018/09/20/1ExploitMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00026.htmlMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2018/Sep/49ExploitMailing ListThird Party Advisory
- https://www.debian.org/security/2018/dsa-4298Third Party Advisory
- https://www.x41-dsec.de/lab/advisories/x41-2018-008-hylafax/ExploitThird Party Advisory
FAQ
What is CVE-2018-17141?
CVE-2018-17141 is a vulnerability with a CVSS score of 9.8 (CRITICAL). HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit enabled, which is mishandled in FaxModem::writeECMDat...
How severe is CVE-2018-17141?
CVE-2018-17141 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-17141?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Hylafax Hylafax, Hylafax Hylafax\+.