TROYANOSYVIRUS
Retour aux CVEs

CVE-2022-23124

CRITICAL
9.8

Description

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_finderinfo method. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-15870.

Details CVE

Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie3/28/2023
Derniere modification11/4/2025
Sourcenvd
Observations honeypot0

Produits affectes

debian:debian_linuxnetatalk:netatalk

Faiblesses (CWE)

CWE-125CWE-125

References

https://security.gentoo.org/glsa/202311-02(zdi-disclosures@trendmicro.com)
https://www.debian.org/security/2023/dsa-5503(zdi-disclosures@trendmicro.com)
https://security.gentoo.org/glsa/202311-02(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2023/dsa-5503(af854a3a-2127-422b-91ae-364da2661108)
https://www.kb.cert.org/vuls/id/709991(af854a3a-2127-422b-91ae-364da2661108)
https://www.zerodayinitiative.com/advisories/ZDI-22-525/(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.