CVE-2008-5718: OS Command Injection
The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute arbitrary commands via shell metacharacters in a print request, as demonstrated using a crafted Title.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5718?
CVE-2008-5718 has been assigned a moderate severity level due to its potential to allow remote command execution.
How do I fix CVE-2008-5718?
To fix CVE-2008-5718, upgrade to Netatalk version 2.0.4-beta2 or later.
What types of systems are affected by CVE-2008-5718?
CVE-2008-5718 affects multiple versions of the Netatalk software, specifically versions prior to 2.0.4-beta2.
What can an attacker do by exploiting CVE-2008-5718?
An attacker exploiting CVE-2008-5718 can execute arbitrary commands on the affected system through crafted print requests.
Is CVE-2008-5718 specific to a certain version of Netatalk?
Yes, CVE-2008-5718 specifically affects Netatalk versions up to and including 2.0.3.