Lucene search

K
zdiNCC Group EDG (Alex Plaskett, Cedric Halbronn, Aaron Adams)ZDI-22-527
HistoryMar 23, 2022 - 12:00 a.m.

(Pwn2Own) Netatalk parse_entries Improper Handling of Exceptional Conditions Remote Code Execution Vulnerability

2022-03-2300:00:00
NCC Group EDG (Alex Plaskett, Cedric Halbronn, Aaron Adams)
www.zerodayinitiative.com
23

0.053 Low

EPSS

Percentile

93.1%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries function. The issue results from the lack of proper error handling when parsing AppleDouble entries. An attacker can leverage this vulnerability to execute code in the context of root.