CVE-2013-5680

Heap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote attackers to cause a denial of service (child hang) or execute arbitrary code via a long USER command.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
lee_howardhylafax\+
5.2.4
lee_howardhylafax\+
5.2.5
lee_howardhylafax\+
5.2.6
lee_howardhylafax\+
5.2.7
lee_howardhylafax\+
5.2.8
lee_howardhylafax\+
5.2.9
lee_howardhylafax\+
5.3.0
lee_howardhylafax\+
5.4.1
lee_howardhylafax\+
5.4.2
lee_howardhylafax\+
5.5.0
lee_howardhylafax\+
5.5.1
lee_howardhylafax\+
5.5.2
lee_howardhylafax\+
5.5.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
hylafax
bullseye
3:6.0.7-3.1
fixed
bookworm
3:6.0.7-5
fixed
sid
3:6.0.7-11
fixed
trixie
3:6.0.7-11
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
hylafax
raring
not-affected
quantal
not-affected
precise
not-affected
lucid
not-affected