CVE-2013-5680: Lee Howard Hylafax+

Medium severity, CVSS 6.8. EPSS: 7.9% chance of exploitation in the next 30 days.

Heap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote attackers to cause a denial of service (child hang) or execute arbitrary code via a long USER command.

Affected products

  • Lee Howard Hylafax+: version 5.2.4 only; version 5.2.5 only; version 5.2.6 only; version 5.2.7 only; version 5.2.8 only; version 5.2.9 only; …

Published 2014-04-06. Last modified 2026-06-16.