Bugtraq mailing list archives

Re: hylafax


From: "Przemyslaw Frasunek" <venglin () freebsd lublin pl>
Date: Sat, 13 Oct 2001 21:31:29 +0200

There are some format strings vulnerbilities in the lastest hylafax
package
try faxrm -h %x 1 or faxalter -h %x -D 1 for "proof of concept".

an exploit for this one:
http://www.frasunek.com/sources/security/security/hylafax.pl

--
* Fido: 2:480/124 ** WWW: http://www.frasunek.com/ ** NIC-HDL: PMF9-RIPE *
* Inet: przemyslaw () frasunek com ** PGP: D48684904685DF43EA93AFA13BE170BF *


Current thread: