The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| netatalk | open_source_apple_file_share_protocol_suite | 1.5_pre6 |
| redhat | fedora_core | core_3.0 |
| mandrakesoft | mandrake_linux | 9.2 |
| redhat | fedora_core | core_2.0 |
| mandrakesoft | mandrake_linux | 10.0 |
| mandrakesoft | mandrake_linux_corporate_server | 2.1 |
| mandrakesoft | mandrake_linux | 10.1 |
| netatalk | open_source_apple_file_share_protocol_suite | 1.6.4 |
| netatalk | open_source_apple_file_share_protocol_suite | 1.6.1 |
The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute arbitrary commands via shell metacharacters in a print request, as demonstrated using a crafted Title.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| netatalk | netatalk | 1.6.4 |
| netatalk | netatalk | 1.4.99-0.20000927 |
| netatalk | netatalk | 1.5pre3 |
| netatalk | netatalk | 1.5.5 |
| netatalk | netatalk | 1.6.0 |
| netatalk | netatalk | 1.5.1.1 |
| netatalk | netatalk | 1.5pre8 |
| netatalk | netatalk | 1.6.1 |
| netatalk | netatalk | 1.5pre4 |
| netatalk | netatalk | 1.6.2 |
| netatalk | netatalk | 2.0.1 |
| netatalk | netatalk | 1.5.1 |
| netatalk | netatalk | 1.4.99-0.20001108 |
| netatalk | netatalk | 1.5pre7 |
| netatalk | netatalk | 2.0 |
| netatalk | netatalk | 1.5.3.1 |
| netatalk | netatalk | 1.6.3 |
| netatalk | netatalk | * |
| netatalk | netatalk | 2.0.0 |
| netatalk | netatalk | 1.6.4a |
| netatalk | netatalk | 1.5 |
| netatalk | netatalk | 1.5pre6 |
| netatalk | netatalk | 1.5pre5 |
| netatalk | netatalk | 2.0.2 |
| netatalk | netatalk | 1.5.2 |
| netatalk | netatalk | 1.5.0 |
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-787,CWE-787,CWE-787,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| synology | router_manager | * |
| synology | skynas | - |
| netatalk | netatalk | * |
| synology | vs960hd_firmware | - |
| synology | diskstation_manager | * |
| debian | debian_linux | 9.0 |