PT-2008-6770 · Netatalk+1 · Netatalk+1
CVE-2008-5718
·
Publicado
2008-12-26
·
Atualizado
2023-08-25
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Netatalk versions prior to 2.0.4-beta2
Description
The issue allows remote attackers to execute arbitrary commands via shell metacharacters in a print request. This can be achieved by using certain variables in a pipe command for the print file, as demonstrated using a crafted Title.
Recommendations
For versions prior to 2.0.4-beta2, update to version 2.0.4-beta2 or later to resolve the issue. As a temporary workaround, consider restricting the use of pipe commands in print files to minimize the risk of exploitation.
Correção
RCE
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Netatalk