Steve Kemp from the Debian Security Audit project discovered that gfax, a GNOME frontend for fax programs, uses temporary files in an unsafe manner which may be exploited to execute arbitrary commands with the privileges of the root user.
For the old stable distribution (sarge) this problem has been fixed in version 0.4.2-11sarge1.
The stable distribution (etch) is not affected by this problem.
The unstable distribution (sid) is not affected by this problem.
We recommend that you upgrade your gfax package.
MD5 checksums of the listed files are available in the original advisory.