GLSA-200501-21 : HylaFAX: hfaxd unauthorized login vulnerability

high Nessus Plugin ID 16412

Synopsis

The remote Gentoo host is missing one or more security-related patches.

Description

The remote host is affected by the vulnerability described in GLSA-200501-21 (HylaFAX: hfaxd unauthorized login vulnerability)

The code used by hfaxd to match a given username and hostname with an entry in the hosts.hfaxd file is insufficiently protected against malicious entries.
Impact :

If the HylaFAX installation uses a weak hosts.hfaxd file, a remote attacker could authenticate using a malicious username or hostname and bypass the intended access restrictions.
Workaround :

As a workaround, administrators may consider adding passwords to all entries in the hosts.hfaxd file.

Solution

All HylaFAX users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=net-misc/hylafax-4.2.0-r2' Note: Due to heightened security, weak entries in the hosts.hfaxd file may no longer work. Please see the HylaFAX documentation for details of accepted syntax in the hosts.hfaxd file.

See Also

https://marc.info/?l=hylafax&m=110545119911558&w=2

https://security.gentoo.org/glsa/200501-21

Plugin Details

Severity: High

ID: 16412

File Name: gentoo_GLSA-200501-21.nasl

Version: 1.20

Type: local

Published: 2/14/2005

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.8

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:gentoo:linux:hylafax, cpe:/o:gentoo:linux

Required KB Items: Host/local_checks_enabled, Host/Gentoo/release, Host/Gentoo/qpkg-list

Patch Publication Date: 1/11/2005

Reference Information

CVE: CVE-2004-1182

GLSA: 200501-21