First published: Fri Dec 26 2008(Updated: )
The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute arbitrary commands via shell metacharacters in a print request, as demonstrated using a crafted Title.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netatalk | <=2.0.3 | |
Netatalk | =1.4.99-0.20000927 | |
Netatalk | =1.4.99-0.20001108 | |
Netatalk | =1.5-rc1 | |
Netatalk | =1.5-rc2 | |
Netatalk | =1.5.0 | |
Netatalk | =1.5.1 | |
Netatalk | =1.5.1.1 | |
Netatalk | =1.5.2 | |
Netatalk | =1.5.3.1 | |
Netatalk | =1.5.5 | |
Netatalk | =1.5pre3 | |
Netatalk | =1.5pre4 | |
Netatalk | =1.5pre5 | |
Netatalk | =1.5pre6 | |
Netatalk | =1.5pre7 | |
Netatalk | =1.5pre8 | |
Netatalk | =1.6.0 | |
Netatalk | =1.6.1 | |
Netatalk | =1.6.2 | |
Netatalk | =1.6.3 | |
Netatalk | =1.6.4 | |
Netatalk | =1.6.4a | |
Netatalk | =2.0-alpha1 | |
Netatalk | =2.0-alpha2 | |
Netatalk | =2.0-beta1 | |
Netatalk | =2.0-beta2 | |
Netatalk | =2.0-rc1 | |
Netatalk | =2.0-rc2 | |
Netatalk | =2.0.0 | |
Netatalk | =2.0.1 | |
Netatalk | =2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5718 has been assigned a moderate severity level due to its potential to allow remote command execution.
To fix CVE-2008-5718, upgrade to Netatalk version 2.0.4-beta2 or later.
CVE-2008-5718 affects multiple versions of the Netatalk software, specifically versions prior to 2.0.4-beta2.
An attacker exploiting CVE-2008-5718 can execute arbitrary commands on the affected system through crafted print requests.
Yes, CVE-2008-5718 specifically affects Netatalk versions up to and including 2.0.3.