LWN.net Logo

netatalk: command injection vulnerability

Package(s):netatalk CVE #(s):CVE-2008-5718
Created:January 16, 2009 Updated:March 26, 2009
Description: From the Debian advisory: It was discovered that netatalk, an implementation of the AppleTalk suite, is affected by a command injection vulnerability when processing PostScript streams via papd. This could lead to the execution of arbitrary code. Please note that this only affects installations that are configured to use a pipe command in combination with wildcard symbols substituted with values of the printed job.
Alerts:
Fedora FEDORA-2009-3069 2009-03-26
Fedora FEDORA-2009-3064 2009-03-26
SuSE SUSE-SR:2009:004 2009-02-17
Debian DSA-1704-2 2009-01-30
Debian DSA-1705-1 2009-01-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds