CVE-2022-45188
published 2022-11-12CVE-2022-45188: Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.59%
44.1th percentile
Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | netatalk | < netatalk 3.1.12~ds-8+deb11u1 (bullseye) | netatalk 3.1.12~ds-8+deb11u1 (bullseye) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| netatalk | netatalk | <= 3.1.13 | — |
| netatalk | netatalk | >= 0 < 3.1.12~ds-8+deb11u1 | 3.1.12~ds-8+deb11u1 |
| netatalk | netatalk | >= 0 < 3.1.15~ds-1 | 3.1.15~ds-1 |
| netatalk | netatalk | >= 0 < 3.1.15~ds-1 | 3.1.15~ds-1 |
| netatalk | netatalk | >= 0 < 3.1.12~ds-4ubuntu0.20.04.1 | 3.1.12~ds-4ubuntu0.20.04.1 |
| netatalk | netatalk | >= 0 < 3.1.12~ds-9ubuntu0.22.04.1 | 3.1.12~ds-9ubuntu0.22.04.1 |
| netatalk | netatalk | >= 0 < 2.2.2-1ubuntu2.2+esm1 | 2.2.2-1ubuntu2.2+esm1 |
| netatalk | netatalk | >= 0 < 2.2.5-1ubuntu0.2+esm1 | 2.2.5-1ubuntu0.2+esm1 |
| netatalk | netatalk | >= 0 < 2.2.6-1ubuntu0.18.04.2+esm1 | 2.2.6-1ubuntu0.18.04.2+esm1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
netatalk vulnerabilities
osv·2023-06-08·CVSS 8.8
CVE-2021-31439 [HIGH] netatalk vulnerabilities
netatalk vulnerabilities
It was discovered that Netatalk did not properly validate the length of
user-supplied data in the DSI structures. A remote attacker could possibly
use this issue to execute arbitrary code with the privileges of the user
invoking the programs. This issue only affected Ubuntu 20.04 LTS and Ubuntu
22.04 LTS. (CVE-2021-31439)
It was discovered that Netatalk did not properly validate the length of
user-supplied data in the ad_addcomment function. A remote attacker could
possibly use this issue to execute arbitrary code with root privileges.
This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-0194)
It was discovered that Netatalk did not properly handle errors when parsing
AppleDouble entries. A remote attacker could possibly use this issue to
ex
OSV
CVE-2022-45188: Netatalk through 3
osv·2022-11-12·CVSS 7.8
CVE-2022-45188 [HIGH] CVE-2022-45188: Netatalk through 3
Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
GHSA
GHSA-xxj8-gh7w-f786: Netatalk through 3
ghsa_unreviewed·2022-11-12
CVE-2022-45188 [HIGH] CWE-122 GHSA-xxj8-gh7w-f786: Netatalk through 3
Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
Ubuntu
Netatalk vulnerabilities
vendor_ubuntu·2023-06-08·CVSS 8.8
CVE-2022-23123 [HIGH] Netatalk vulnerabilities
Title: Netatalk vulnerabilities
Summary: Several security issues were fixed in Netatalk.
It was discovered that Netatalk did not properly validate the length of
user-supplied data in the DSI structures. A remote attacker could possibly
use this issue to execute arbitrary code with the privileges of the user
invoking the programs. This issue only affected Ubuntu 20.04 LTS and Ubuntu
22.04 LTS. (CVE-2021-31439)
It was discovered that Netatalk did not properly validate the length of
user-supplied data in the ad_addcomment function. A remote attacker could
possibly use this issue to execute arbitrary code with root privileges.
This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-0194)
It was discovered that Netatalk did not properly handle errors when parsing
AppleDoub
Debian
CVE-2022-45188: netatalk - Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting ...
vendor_debian·2022·CVSS 7.8
CVE-2022-45188 [HIGH] CVE-2022-45188: netatalk - Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting ...
Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
Scope: local
bullseye: resolved (fixed in 3.1.12~ds-8+deb11u1)
forky: resolved (fixed in 3.1.15~ds-1)
sid: resolved (fixed in 3.1.15~ds-1)
trixie: resolved (fixed in 3.1.15~ds-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2023/05/msg00018.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZYWSGVA6WXREMB6PV56HAHKU7R6KPOP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GEAFLA5L2SHOUFBAGUXIF2TZLGBXGJKT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SG6WZW5LXFVH3P7ZVZRGHUVJEMEFKQLI/https://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.13.htmlhttps://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.14.htmlhttps://rushbnt.github.io/bug%20analysis/netatalk-0day/https://security.gentoo.org/glsa/202311-02https://sourceforge.net/projects/netatalk/files/netatalk/https://www.debian.org/security/2023/dsa-5503https://lists.debian.org/debian-lts-announce/2023/05/msg00018.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZYWSGVA6WXREMB6PV56HAHKU7R6KPOP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GEAFLA5L2SHOUFBAGUXIF2TZLGBXGJKT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SG6WZW5LXFVH3P7ZVZRGHUVJEMEFKQLI/https://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.13.htmlhttps://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.14.htmlhttps://rushbnt.github.io/bug%20analysis/netatalk-0day/https://security.gentoo.org/glsa/202311-02https://sourceforge.net/projects/netatalk/files/netatalk/https://www.debian.org/security/2023/dsa-5503
2022-11-12
Published