ZDI-CAN-17646: ZDI-23-094: Netatalk dsi_writeinit Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published Feb 6, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Netatalk
Event History
Feb 6, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Jan 29, 2025
Advisory Published
via ZDI·07:05 AM
Frequently Asked Questions
1
What is the vulnerability ID for this Netatalk vulnerability?
The vulnerability ID for this Netatalk vulnerability is ZDI-CAN-17646.
2
What is the severity of the ZDI-CAN-17646 vulnerability?
The severity of the ZDI-CAN-17646 vulnerability is critical, with a severity value of 9.8.
3
How can remote attackers exploit the ZDI-CAN-17646 vulnerability?
Remote attackers can exploit the ZDI-CAN-17646 vulnerability to execute arbitrary code on affected installations of Netatalk, without requiring authentication.
4
Which function within Netatalk is affected by the ZDI-CAN-17646 vulnerability?
The specific flaw exists within the dsi_writeinit function in Netatalk.
5
Are there any references available for the ZDI-CAN-17646 vulnerability?
Yes, you can find references for the ZDI-CAN-17646 vulnerability at the following links: [link1], [link2], [link3].