Vulnerabilities > CVE-2022-45188 - Out-of-bounds Write vulnerability in multiple products

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH

Summary

Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).

Vulnerable Configurations

Part Description Count
Application
Netatalk
60
OS
Debian
2
OS
Fedoraproject
3

Common Weakness Enumeration (CWE)