OS Command Injection in Mgetty+Sendfax - CVE-2018-16741

 

OS Command Injection in Mgetty+Sendfax - CVE-2018-16741

Published: October 8, 2018


Vulnerability identifier: #VU15169
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16741
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary shell commands on the target system.

The vulnerability exists within mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() due to improper sanitization of shell metacharacters. A local user can use ||, &&, or > characters within a file created by the "faxq-helper activate <jobid>" command to execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Mgetty+Sendfax
mgetty (Debian package)
mgetty
Opensuse
Fedora
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)

How to mitigate CVE-2018-16741

Install update from vendor's website.

Mgetty+Sendfax - update to 1.2.1
mgetty (Debian package) - update to 1.1.36-3+deb9u1
mgetty - addressed in versions 1.1.37-10.fc28, 1.1.37-11.fc29
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007

External References

Related Security Bulletins