CVE-2022-22995
Published: 25 March 2022
The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
Priority
Status
Package | Release | Status |
---|---|---|
netatalk Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(code not present)
|
focal |
Released
(3.1.12~ds-4ubuntu0.20.04.3+esm1)
Available with Ubuntu Pro |
|
jammy |
Released
(3.1.12~ds-9ubuntu0.22.04.3+esm1)
Available with Ubuntu Pro |
|
lunar |
Ignored
(end of life, was needs-triage)
|
|
mantic |
Ignored
(end of life, was needed)
|
|
noble |
Not vulnerable
(3.1.18~ds-1build4)
|
|
trusty |
Not vulnerable
(code not present)
|
|
upstream |
Released
(3.1.18~ds-1)
|
|
xenial |
Not vulnerable
(code not present)
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 9.8 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References
- https://netatalk.sourceforge.io/CVE-2022-22995.php
- https://github.com/Netatalk/netatalk/pull/509
- https://github.com/Netatalk/netatalk/commit/9eb6d9d0ac17dca210ccbf05476a925a6b379dfb
- https://www.cve.org/CVERecord?id=CVE-2022-22995
- https://ubuntu.com/security/notices/USN-6786-1
- NVD
- Launchpad
- Debian