PT-2023-1329 · Netatalk+4 · Netatalk+4

Corentin Bayet

+4

·

Publicado

2023-02-06

·

Atualizado

2024-12-26

·

CVE-2022-43634

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Netatalk (affected versions not specified)
Description This issue allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this issue. The specific flaw exists within the dsi writeinit function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this issue to execute code in the context of root.
Recommendations At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

RCE

Heap Based Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-5918
ALT-PU-2023-5932
ALT-PU-2023-5933
ALT-PU-2024-17688
BDU:2023-00621
CVE-2022-43634
DLA-3426-1
DSA-5503-1
SUSE-SU-2023:0316-1
SUSE-SU-2023_0316-1
USN-6146-1
ZDI-23-094

Produtos afetados

Alt Linux
Linuxmint
Netatalk
Suse
Ubuntu