Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
References
Link | Resource |
---|---|
https://rushbnt.github.io/bug%20analysis/netatalk-0day/ | Exploit Third Party Advisory |
https://sourceforge.net/projects/netatalk/files/netatalk/ | Release Notes Third Party Advisory |
https://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.13.html | Release Notes Third Party Advisory |
https://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.14.html | Broken Link |
Configurations
Information
Published : 2022-11-11 21:15
Updated : 2022-11-17 08:16
NVD link : CVE-2022-45188
Mitre link : CVE-2022-45188
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
netatalk_project
- netatalk