PT-2008-6770 · Netatalk+1 · Netatalk+1

Published

2008-12-26

·

Updated

2023-08-25

·

CVE-2008-5718

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Netatalk versions prior to 2.0.4-beta2
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in a print request. This can be achieved by using certain variables in a pipe command for the print file, as demonstrated using a crafted Title.
Recommendations For versions prior to 2.0.4-beta2, update to version 2.0.4-beta2 or later to resolve the issue. As a temporary workaround, consider restricting the use of pipe commands in print files to minimize the risk of exploitation.

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1957
ALT-PU-2023-5152
CVE-2008-5718
DSA-1705-1
DTSA-183-1

Affected Products

Alt Linux
Netatalk