Gert Doering's vulnerability profile centers on mgetty, a focused telephony and modem utility that, despite limited scope, occupies a niche role in legacy communication and fax infrastructure where it remains embedded in production environments. The recurring weakness classes—chiefly link-following and file-access flaws—reflect the product's interaction with filesystem operations and symlink handling in lower-level system components, areas where defensive coding becomes critical in utilities with elevated privilege. Public exploit code has been developed for vulnerabilities in this product, and defenders should treat mgetty instances as requiring careful inventory and timely patching. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gert Doering over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0516HIGH cnd.c in mgetty 1.1.28 and earlier does not properly filter non-printable characters and quotes, which may allow remote attackers to execute arbitrary commands via shell metacharac | Aug 18, 2003 | 7.5 | 20 | NO | NO |
CVE-2002-1391HIGH Buffer overflow in cnd-program for mgetty before 1.1.29 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Caller ID string with a long | Jan 17, 2003 | 7.5 | 20 | NO | NO |
CVE-2008-4936MEDIUM faxspool in mgetty 1.1.36 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/faxsp.##### temporary file. | Nov 5, 2008 | 6.9 | 18 | NO | NO |
The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/. | Oct 20, 2000 | 2.1 | 17 | NO | YES |
faxspool in mgetty before 1.1.29 uses a world-writable spool directory for outgoing faxes, which allows local users to modify fax transmission privileges. | Jan 17, 2003 | 2.1 | 11 | NO | NO |
mgetty 1.1.22 allows local users to overwrite arbitrary files via a symlink attack in some configurations. | Mar 12, 2001 | 1.2 | 10 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gert Doering.
Media articles that mention a CVE ID that affects a product developed by Gert Doering — matched by CVE ID, not by vendor name.