Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-44068

Опубликовано: 21 мая 2026
Источник: debian
EPSS Низкий

Описание

Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended metadata namespace via crafted EA names.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
netatalkfixed4.4.3~ds-1package

Примечания

  • https://netatalk.io/security/CVE-2026-44068

EPSS

Процентиль: 25%
0.00322
Низкий

Связанные уязвимости

CVSS3: 7.6
ubuntu
3 месяца назад

Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended metadata namespace via crafted EA names.

CVSS3: 7.6
nvd
3 месяца назад

Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended metadata namespace via crafted EA names.

CVSS3: 7.6
github
3 месяца назад

Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended metadata namespace via crafted EA names.

EPSS

Процентиль: 25%
0.00322
Низкий