CVE-2022-45188: Buffer Overflow
Netatalk through 3.1.13 has an afpgetappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/netatalkto a version that resolves this vulnerability.Fixed in 3.1.12~ds-3+deb10u4Fixed in 3.1.12~ds-8+deb11u1Fixed in 3.1.18~ds-1
Event History
Frequently Asked Questions
What is CVE-2022-45188?
CVE-2022-45188 is a vulnerability in Netatalk through 3.1.13 that allows remote attackers to execute arbitrary code via a crafted .appl file.
What is the severity of CVE-2022-45188?
CVE-2022-45188 has a severity rating of 7.8 (high).
Which platforms are affected by CVE-2022-45188?
Platforms such as FreeBSD (used for TrueNAS) are affected by CVE-2022-45188.
How can remote root access be achieved through CVE-2022-45188?
CVE-2022-45188 can provide remote root access on certain platforms, such as FreeBSD, by exploiting the afp_getappl heap-based buffer overflow vulnerability.
Is there a fix available for CVE-2022-45188?
Yes, a fix is available for CVE-2022-45188. The affected software versions should be updated to versions that have addressed the vulnerability.