UBUNTU-CVE-2022-0194
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-0194
UBUNTU-CVE-2022-0194
Summary:
Details: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15876. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root.]
References: https://ubuntu.com/security/CVE-2022-0194, https://kb.cert.org/vince/comm/case/267/, https://sourceforge.net/p/netatalk/mailman/message/37628321/, https://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.13.html, https://ubuntu.com/security/notices/USN-6146-1, https://www.cve.org/CVERecord?id=CVE-2022-0194
Affected packages
Package
Name: netatalk
Purl: pkg:deb/ubuntu/netatalk?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
