ZDI-CAN-15870: (Pwn2Own) Netatalk get_finderinfo Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getfinderinfo method. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-15870?
The severity of ZDI-CAN-15870 is considered to be critical due to the potential for remote attackers to disclose sensitive information without authentication.
How do I fix ZDI-CAN-15870?
To fix ZDI-CAN-15870, upgrade to the latest version of Netatalk that addresses this vulnerability.
What type of vulnerability is ZDI-CAN-15870?
ZDI-CAN-15870 is a remote information disclosure vulnerability in Netatalk.
Who is affected by ZDI-CAN-15870?
Any installations of Netatalk that have not been patched may be affected by ZDI-CAN-15870.
Can ZDI-CAN-15870 be exploited without authentication?
Yes, ZDI-CAN-15870 can be exploited by attackers without the need for authentication.