PT-2023-1329 · Netatalk+4 · Netatalk+4

Corentin Bayet

+4

·

Published

2023-02-06

·

Updated

2024-12-26

·

CVE-2022-43634

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Netatalk (affected versions not specified)
Description This issue allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this issue. The specific flaw exists within the dsi writeinit function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this issue to execute code in the context of root.
Recommendations At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

RCE

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-5918
ALT-PU-2023-5932
ALT-PU-2023-5933
ALT-PU-2024-17688
BDU:2023-00621
CVE-2022-43634
DLA-3426-1
DSA-5503-1
SUSE-SU-2023:0316-1
SUSE-SU-2023_0316-1
USN-6146-1
ZDI-23-094

Affected Products

Alt Linux
Linuxmint
Netatalk
Suse
Ubuntu