Описание
A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service via crafted character set data.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | |
| esm-apps-legacy/xenial | not-affected | |
| esm-apps/bionic | not-affected | |
| esm-apps/focal | released | 3.1.12~ds-4ubuntu0.20.04.4+esm1 |
| esm-apps/jammy | released | 3.1.12~ds-9ubuntu0.22.04.4+esm1 |
| esm-apps/noble | released | 3.1.18~ds-1ubuntu0.1~esm2 |
| esm-apps/resolute | released | 4.2.3~ds-2.1ubuntu0.1 |
| esm-infra-legacy/trusty | not-affected | |
| jammy | needed | |
| noble | needed |
Показывать по
EPSS
7.5 High
CVSS3
Связанные уязвимости
A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service via crafted character set data.
A missing output length bounds check in pull_charset_flags() in Netata ...
A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service via crafted character set data.
EPSS
7.5 High
CVSS3