netatalk.io

Netatalk Security Advisory

Subject Arbitrary code execution in setfilparams
CVE ID# CVE-2022-23122
Severity Critical
Disclosure Date 2022/03/22
Affected Versions 3.0.0 - 3.1.12
Summary Lack of validation of user-input data leads remote code execution in the setfilparams function

Description

This vulnerability allows remote attackers to execute arbitrary code on affected Netatalk installations without requiring authentication.

The flaw resides in the setfilparams function, where user-supplied data is not properly validated before being copied into a fixed-length stack-based buffer.

An attacker can exploit this vulnerability to execute code with root-level privileges.

Patch Availability

Apply the patch CVE-2022-0194,CVE-2022-23122,CVE-2022-23123,CVE-2022-23124.patch to hotfix your local Netatalk deployment.

Additionally, Netatalk 3.1.13 has been released which contains the security patch. Netatalk administrators are advised to upgrade to this version or apply the patch as soon as possible.

CVSS Calculation

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8)

Workaround

None.

Credits

Vulnerability reported by:

Orange Tsai (@orange_8361) from DEVCORE Research Team

Patch developed by:

Ralph Boehme of the Netatalk and Samba teams

References


Go back to the Security Policy.