UBUNTU-CVE-2022-23124
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-23124
UBUNTU-CVE-2022-23124
Summary:
Details: This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_finderinfo method. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-15870. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_finderinfo method. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root.]
References: https://ubuntu.com/security/CVE-2022-23124, https://kb.cert.org/vince/comm/case/267/, https://sourceforge.net/p/netatalk/mailman/message/37628321/, https://ubuntu.com/security/notices/USN-6146-1, https://www.cve.org/CVERecord?id=CVE-2022-23124
Affected packages
Package
Name: netatalk
Purl: pkg:deb/ubuntu/netatalk?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
