CVE-2013-5680

medium
Published 2014-04-06 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Heap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote attackers to cause a denial of service (child hang) or execute arbitrary code via a long USER command.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-5680

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://hylafax.sourceforge.net/news/5.5.4.php

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Application impact

VendorProductVersionsFixed
lee_howardhylafax\+5.2.4
lee_howardhylafax\+5.2.5
lee_howardhylafax\+5.2.6
lee_howardhylafax\+5.2.7
lee_howardhylafax\+5.2.8
lee_howardhylafax\+5.2.9
lee_howardhylafax\+5.3.0
lee_howardhylafax\+5.4.1
lee_howardhylafax\+5.4.2
lee_howardhylafax\+5.5.0
lee_howardhylafax\+5.5.1
lee_howardhylafax\+5.5.2
lee_howardhylafax\+5.5.3

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.