CVE-2022-23124: (Pwn2Own) Netatalk get_finderinfo Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getfinderinfo method. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23124?
CVE-2022-23124 is a vulnerability in Netatalk that allows remote attackers to disclose sensitive information.
How can remote attackers exploit CVE-2022-23124?
Remote attackers can exploit CVE-2022-23124 without authentication by taking advantage of the lack of proper validation in the get_finderinfo method.
What is the severity of CVE-2022-23124?
CVE-2022-23124 has a severity rating of 9.8, which is considered critical.
What is the affected software of CVE-2022-23124?
The affected software includes Netatalk versions up to and exclusive of 3.1.13.
How can I fix CVE-2022-23124?
To fix CVE-2022-23124, it is recommended to update Netatalk to version 3.1.13 or higher.