PT-2008-6770 · Netatalk+1 · Netatalk+1
Published
2008-12-26
·
Updated
2023-08-25
·
CVE-2008-5718
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Netatalk versions prior to 2.0.4-beta2
Description
The issue allows remote attackers to execute arbitrary commands via shell metacharacters in a print request. This can be achieved by using certain variables in a pipe command for the print file, as demonstrated using a crafted Title.
Recommendations
For versions prior to 2.0.4-beta2, update to version 2.0.4-beta2 or later to resolve the issue. As a temporary workaround, consider restricting the use of pipe commands in print files to minimize the risk of exploitation.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Netatalk