Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-45188
HistoryNov 12, 2022 - 12:00 a.m.

CVE-2022-45188

2022-11-1200:00:00
ubuntu.com
ubuntu.com
20
netatalk buffer overflow
code execution
remote root access
freebsd
truenas
cve-2022-45188

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

51.2%

Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow
resulting in code execution via a crafted .appl file. This provides remote
root access on some platforms such as FreeBSD (used for TrueNAS).

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchnetatalk< 2.2.6-1ubuntu0.18.04.2+esm1UNKNOWN
ubuntu20.04noarchnetatalk< 3.1.12~ds-4ubuntu0.20.04.1UNKNOWN
ubuntu22.04noarchnetatalk< 3.1.12~ds-9ubuntu0.22.04.1UNKNOWN
ubuntu22.10noarchnetatalk< 3.1.13~ds-2ubuntu0.22.10.1UNKNOWN
ubuntu14.04noarchnetatalk< 2.2.2-1ubuntu2.2+esm1UNKNOWN
ubuntu16.04noarchnetatalk< 2.2.5-1ubuntu0.2+esm1UNKNOWN

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

51.2%