MidnightBSD

Advisories for netatalk

CVE-2004-0974 LOW

The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
netatalk open_source_apple_file_share_protocol_suite 1.5_pre6
redhat fedora_core core_3.0
mandrakesoft mandrake_linux 9.2
redhat fedora_core core_2.0
mandrakesoft mandrake_linux 10.0
mandrakesoft mandrake_linux_corporate_server 2.1
mandrakesoft mandrake_linux 10.1
netatalk open_source_apple_file_share_protocol_suite 1.6.4
netatalk open_source_apple_file_share_protocol_suite 1.6.1
CVE-2008-5718 HIGH

The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute arbitrary commands via shell metacharacters in a print request, as demonstrated using a crafted Title.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
netatalk netatalk 1.6.4
netatalk netatalk 1.4.99-0.20000927
netatalk netatalk 1.5pre3
netatalk netatalk 1.5.5
netatalk netatalk 1.6.0
netatalk netatalk 1.5.1.1
netatalk netatalk 1.5pre8
netatalk netatalk 1.6.1
netatalk netatalk 1.5pre4
netatalk netatalk 1.6.2
netatalk netatalk 2.0.1
netatalk netatalk 1.5.1
netatalk netatalk 1.4.99-0.20001108
netatalk netatalk 1.5pre7
netatalk netatalk 2.0
netatalk netatalk 1.5.3.1
netatalk netatalk 1.6.3
netatalk netatalk *
netatalk netatalk 2.0.0
netatalk netatalk 1.6.4a
netatalk netatalk 1.5
netatalk netatalk 1.5pre6
netatalk netatalk 1.5pre5
netatalk netatalk 2.0.2
netatalk netatalk 1.5.2
netatalk netatalk 1.5.0
CVE-2018-1160 HIGH

Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,CWE-787,CWE-787,

Products Affected

Vendor Product Version
synology router_manager *
synology skynas -
netatalk netatalk *
synology vs960hd_firmware -
synology diskstation_manager *
debian debian_linux 9.0