netatalk.io

Netatalk Security Advisory

Subject Information leak in getdirparams
CVE ID# CVE-2022-23123
Date 2022/03/21 advisory published retroactively; date is approximate
Versions 3.0.0 - 3.1.12, 1.5.0 - 2.2.6
Summary Lack of validation of user-input data in the getdirparams function allows for reading past of allocated buffer

Description

This vulnerability allows remote attackers to disclose sensitive information on affected Netatalk installations without requiring authentication.

The flaw resides in the getdirparams method, where user-supplied data is not properly validated, leading to a read past the end of an allocated buffer.

An attacker can combine this issue with other vulnerabilities to execute arbitrary code with root-level privileges.

Patch Availability

Apply the patch with git hash 4a8f6c9 to hotfix your local Netatalk deployment.

Additionally, Netatalk 3.1.13 and 2.2.7 have been released which contains the security patch. Netatalk administrators are advised to upgrade to this version or apply the patch as soon as possible.

CVSS Calculation

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N (5.3)

Workaround

None.

Credits

Vulnerability found and reported by:

Orange Tsai (@orange_8361) from DEVCORE Research Team

Patch developed by:

Ralph Boehme of the Netatalk and Samba teams


Go back to the Security Policy.