Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Debian: DSA-1704-2 Critical: Netatalk Command Injection Risk Mitigated

debian
Calendar Grey January 29, 2009
Scroller Debian
Debian has issued an update for netatalk to fix a command injection vulnerability that may permit remote execution of arbitrary code. Installing this upgrade is highly recommended
The update in DSA 1704-1 was incomplete as it missed to escape a few important characters which enabled an attacker to overwrite arbitrary files

Summary

The update in DSA 1704-1 was incomplete as it missed to escape a few
important characters which enabled an attacker to overwrite arbitrary
files.

It was discovered that netatalk, an implementation of the AppleTalk
suite, is affected by a command injection vulnerability when processing
PostScript streams via papd. This is leading to arbitrary remote
code execution. Note that this only affects installations that are
configured to use a pipe command in combination with wildcard symbols
substituted with values of the printed job.

For the stable distribution (etch) this problem has been fixed in
version 2.0.3-4+etch2.

For the unstable distribution (sid) this problem has been fixed in
version 2.0.4~beta2-1.1.

We recommend that you upgrade your netatalk package.


Upgrade Instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given at the end of thi...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: netatalk
CVE ID: CVE-2008-5718

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.