CVE-2022-23121
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries function. The issue results from the lack of proper error handling when parsing AppleDouble entries. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15819.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 18.58%
- CWE
- CWE-755
- Published
- 2023-03-28
- Last modified
- 2026-03-13
Affected products
- Netatalk Netatalk
Weakness type
Related vulnerabilities
- CVE-2021-40402 — An out-of-bounds read vulnerability exists in the RS-274X aperture macro multiple outline primitives functionality of Ge
- CVE-2025-10156 — PickleScan Security Bypass via Bad CRC in ZIP Archive
- CVE-2024-34750 — Apache Tomcat: HTTP/2 excess header handling DoS
- CVE-2024-21907 — Improper Handling of Exceptional Conditions in Newtonsoft.Json
- CVE-2026-27586 — Caddy's mTLS client authentication silently fails open when CA certificate file is missing or malformed
- CVE-2024-30382 — Junos OS and Junos OS Evolved: RPD crash when CoS-based forwarding (CBF) policy is configured
- CVE-2026-21906 — Junos OS: SRX Series: With GRE performance acceleration enabled, receipt of a specific ICMP packet causes the PFE to crash
- CVE-2025-9437 — Rockwell Automation ArmorStart® AOP Denial-of-Service Vulnerability