ZDI-23-094: Netatalk dsi_writeinit Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published Feb 6, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Netatalk
Event History
Feb 6, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Jan 29, 2025
Advisory Published
via ZDI·07:05 AM
Frequently Asked Questions
1
What is the severity of ZDI-23-094?
The severity of ZDI-23-094 is critical, with a CVSS score of 9.8.
2
How does the ZDI-23-094 vulnerability allow remote attackers to execute arbitrary code?
The vulnerability allows remote attackers to execute arbitrary code by exploiting a heap-based buffer overflow in Netatalk's dsi_writeinit function.
3
Is authentication required to exploit the ZDI-23-094 vulnerability?
No, authentication is not required to exploit the ZDI-23-094 vulnerability.
4
What is the affected software of ZDI-23-094?
The affected software of ZDI-23-094 is Netatalk, specifically the Netatalk product.
5
How can I fix the ZDI-23-094 vulnerability?
To fix the ZDI-23-094 vulnerability, update to the latest version of Netatalk and apply any patches or security updates provided by the vendor.