HylaFAX+ versions 5.2.4 through 5.5.3 suffer from a buffer overflow vulnerability. The code path for authenticating users via LDAP allocates a 255-byte buffer (via the C++ “new” operator), and then “strcats” user-supplied data buffered from the inbound FTP control channel. Other code limits the amount of copied data to 506 bytes, and truncates on NULL and “\n”. Thus it is possible for an unauthenticated remote attacker to overflow the heap with a limited character set…. HylaFAX+ versions 5.2.4 through 5.5.3 suffer from a buffer overflow vulnerability. The code path for authenticating users via LDAP allocates a 255-byte buffer (via the C++ “new” operator), and then “strcats” user-supplied data buffered from the inbound FTP control channel. Other code limits the amount of copied data to 506 bytes, and truncates on NULL and “\n”. Thus it is possible for an unauthenticated remote attacker to overflow the heap with a limited character set.
Read more http://packetstormsecurity.com/files/123456/hylafaxplus-overflow.txt