Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-0194

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15876.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.082
EPSS Ranking 91.7%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-0194


Contact Us

Shodan ® - All rights reserved