PT-2022-15865 · Netatalk+4 · Netatalk+4

Aaron Adams

+2

·

Published

2022-03-21

·

Updated

2024-12-26

·

CVE-2022-23121

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netatalk (affected versions not specified)
Description This issue allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this issue. The specific flaw exists within the parse entries function. The issue results from the lack of proper error handling when parsing AppleDouble entries. An attacker can leverage this issue to execute code in the context of root.
Recommendations At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

RCE

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3105
ALT-PU-2023-1957
ALT-PU-2023-5152
ALT-PU-2023-5918
ALT-PU-2023-5932
ALT-PU-2023-5933
ALT-PU-2024-17688
CVE-2022-23121
DLA-3426-1
DLA-3426-2
DSA-5503-1
MGASA-2022-0196
MGASA-2023-0027
SUSE-SU-2022:1184-1
USN-6146-1
ZDI-22-527

Affected Products

Alt Linux
Linuxmint
Netatalk
Suse
Ubuntu