Skip to main content

Vendor/product archive

mgetty_project / mgetty CVEs

Beta · best-effort

8 CVEs tagged to mgetty_project / mgetty0 Critical, 5 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2019-1010189

Published Jul 24, 2019

mgetty prior to version 1.2.1 is affected by: Infinite Loop. The impact is: DoS, the program does never terminates. The component is: g3/g32pbm.c. The attack vector is: Local, the…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1010190

Published Jul 24, 2019

mgetty prior to 1.2.1 is affected by: out-of-bounds read. The impact is: DoS, the program may crash if the memory is not mapped. The component is: putwhitespan() in g3/pbm2g3.c. T…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16745

Published Sep 13, 2018

An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized. It could allow a buffer overflow if long untrusted input…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16744

Published Sep 13, 2018

An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized. It could allow for command injection if untrusted input c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16743

Published Sep 13, 2018

An issue was discovered in mgetty before 1.2.1. In contrib/next-login/login.c, the command-line parameter username is passed unsanitized to strcpy(), which can cause a stack-based…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16742

Published Sep 13, 2018

An issue was discovered in mgetty before 1.2.1. In contrib/scrts.c, a stack-based buffer overflow can be triggered via a command-line parameter.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16741

Published Sep 13, 2018

An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanitize shell metacharacters to prevent command injection. It i…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0517

Published Aug 18, 2003

faxrunqd.in in mgetty 1.1.28 and earlier allows local users to overwrite files via a symlink attack on JOB files.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1