Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23125

Опубликовано: 28 мар. 2023
Источник: redhat
CVSS3: 9.8

Описание

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyapplfile function. When parsing the len element, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15869.

A flaw was found in Netatalk. This vulnerability allows remote attackers to execute arbitrary code (Remote Code Execution) in the context of root via improper validation of user-supplied data length prior to copying it to a fixed-length stack-based buffer in the copyapplfile function.

Отчет

The Netatalk package has a stack-based buffer overflow vulnerability in the copyapplfile() function. This is a result of the lack of validation when handling the appl tag in the appls file when copying its information to a new file. The function reads the appl tag information length but does not validate if it's bigger than the maximum buffer size Netatalk uses to store such data, as a result an unauthenticated attacker can craft a file that'll lead to a stack-based buffer overflow when being copied resulting in a remote code execution in a high privileged context. This vulnerability doesn't affect any supported Red Hat product.

Дополнительная информация

Статус:

Critical
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2417580netatalk: Netatalk: Remote Code Execution via Buffer Overflow in copyapplfile function

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyapplfile function. When parsing the len element, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15869. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyapplfile function. When parsing the len element, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root.]

CVSS3: 9.8
nvd
больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyapplfile function. When parsing the len element, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15869.

CVSS3: 9.8
debian
больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code o ...

CVSS3: 9.8
github
больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyapplfile function. When parsing the len element, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15869.

suse-cvrf
больше 4 лет назад

Security update for netatalk

9.8 Critical

CVSS3