Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Etienne Helluy-Lafont

Researcher fromSynacktiv
#13218of 53,633
20Total CVSS
Vulnerabilities · 2
Critical
2
PT-2023-1329
10
2023-02-06
Netatalk · Netatalk · CVE-2022-43634
**Name of the Vulnerable Software and Affected Versions** Netatalk (affected versions not specified) **Description** This issue allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this issue. The specific flaw exists within the `dsi writeinit` function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this issue to execute code in the context of root. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this issue.
PT-2022-15765
10
2022-03-25
Afp · Afp · CVE-2022-22995
**Name of the Vulnerable Software and Affected Versions** SMB and AFP (affected versions not specified) **Description** The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting this combination of primitives, an attacker can execute arbitrary code. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.