Mgetty is a narrowly scoped modem and fax communication utility that, despite limited product breadth, occupies a durable niche in legacy telecommunications infrastructure and embedded systems. Its vulnerability profile concentrates around OS command injection, buffer boundary violations, and file-access race conditions—weaknesses characteristic of system utilities handling untrusted input from modems and external callers. Defenders maintaining legacy fax and modem gateways should review patches for this vendor; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mgetty Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16744HIGH An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized. It could allow for command injection if untrusted input ca | Sep 13, 2018 | 7.8 | 26 | NO | NO |
CVE-2018-16745HIGH An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized. It could allow a buffer overflow if long untrusted input c | Sep 13, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-16743HIGH An issue was discovered in mgetty before 1.2.1. In contrib/next-login/login.c, the command-line parameter username is passed unsanitized to strcpy(), which can cause a stack-based | Sep 13, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-16742HIGH An issue was discovered in mgetty before 1.2.1. In contrib/scrts.c, a stack-based buffer overflow can be triggered via a command-line parameter. | Sep 13, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-16741HIGH An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanitize shell metacharacters to prevent command injection. It is | Sep 13, 2018 | 7.8 | 25 | NO | NO |
CVE-2019-1010190MEDIUM mgetty prior to 1.2.1 is affected by: out-of-bounds read. The impact is: DoS, the program may crash if the memory is not mapped. The component is: putwhitespan() in g3/pbm2g3.c. Th | Jul 24, 2019 | 5.5 | 20 | NO | NO |
CVE-2019-1010189MEDIUM mgetty prior to version 1.2.1 is affected by: Infinite Loop. The impact is: DoS, the program does never terminates. The component is: g3/g32pbm.c. The attack vector is: Local, the | Jul 24, 2019 | 5.5 | 19 | NO | NO |
CVE-2003-0517MEDIUM faxrunqd.in in mgetty 1.1.28 and earlier allows local users to overwrite files via a symlink attack on JOB files. | Aug 18, 2003 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mgetty Project.
Media articles that mention a CVE ID that affects a product developed by Mgetty Project — matched by CVE ID, not by vendor name.