CVE-2022-22995
Summary
| CVE | CVE-2022-22995 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-25 23:15:00 UTC |
| Updated | 2024-01-04 22:15:00 UTC |
| Description | The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code. |
Risk And Classification
Problem Types: CWE-59
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 37 | All | All | All |
| Operating System | Fedoraproject | Fedora | 38 | All | All | All |
| Operating System | Fedoraproject | Fedora | 39 | All | All | All |
| Application | Netatalk | Netatalk | All | All | All | All |
| Hardware | Westerndigital | My Cloud | - | All | All | All |
| Hardware | Westerndigital | My Cloud Dl2100 | - | All | All | All |
| Operating System | Westerndigital | My Cloud Dl2100 Firmware | All | All | All | All |
| Hardware | Westerndigital | My Cloud Dl4100 | - | All | All | All |
| Operating System | Westerndigital | My Cloud Dl4100 Firmware | All | All | All | All |
| Hardware | Westerndigital | My Cloud Ex2100 | - | All | All | All |
| Operating System | Westerndigital | My Cloud Ex2100 Firmware | All | All | All | All |
| Hardware | Westerndigital | My Cloud Ex2 Ultra | - | All | All | All |
| Operating System | Westerndigital | My Cloud Ex2 Ultra Firmware | All | All | All | All |
| Hardware | Westerndigital | My Cloud Ex4100 | - | All | All | All |
| Operating System | Westerndigital | My Cloud Ex4100 Firmware | All | All | All | All |
| Operating System | Westerndigital | My Cloud Firmware | All | All | All | All |
| Hardware | Westerndigital | My Cloud Home | - | All | All | All |
| Operating System | Westerndigital | My Cloud Home Firmware | All | All | All | All |
| Hardware | Westerndigital | My Cloud Mirror Gen 2 | - | All | All | All |
| Operating System | Westerndigital | My Cloud Mirror Gen 2 Firmware | All | All | All | All |
| Hardware | Westerndigital | My Cloud Pr2100 | - | All | All | All |
| Operating System | Westerndigital | My Cloud Pr2100 Firmware | All | All | All | All |
| Hardware | Westerndigital | My Cloud Pr4100 | - | All | All | All |
| Operating System | Westerndigital | My Cloud Pr4100 Firmware | All | All | All | All |
| Hardware | Westerndigital | Wd Cloud | - | All | All | All |
| Operating System | Westerndigital | Wd Cloud Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 38 Update: netatalk-3.1.18-1.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 38 Update: netatalk-3.1.18-1.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| WDC-22005 Netatalk Security Vulnerabilities | Western Digital | MISC | www.westerndigital.com | |
| [SECURITY] Fedora 37 Update: netatalk-3.1.18-1.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Netatalk: Multiple Vulnerabilities including root remote code execution (GLSA 202311-02) — Gentoo security | GENTOO | security.gentoo.org | |
| [SECURITY] Fedora 37 Update: netatalk-3.1.18-1.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [debian-lts-announce] 20240104 [SECURITY] [DLA 3706-1] netatalk security update | lists.debian.org | ||
| [SECURITY] Fedora 39 Update: netatalk-3.1.18-1.fc39 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 39 Update: netatalk-3.1.18-1.fc39 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Corentin BAYET (@OnlyTheDuck), Etienne HELLUY-LAFONT and Luca MORO (@johncool__) from Synacktiv working with Trend Micro’s Zero Day Initiative
Legacy QID Mappings
- 284623 Fedora Security Update for netatalk (FEDORA-2023-ef901c862c)
- 284624 Fedora Security Update for netatalk (FEDORA-2023-cec97f7b5d)
- 285217 Fedora Security Update for netatalk (FEDORA-2023-39f0ec3879)
- 503372 Alpine Linux Security Update for netatalk
- 506123 Alpine Linux Security Update for netatalk
- 6000420 Debian Security Update for netatalk (DLA 3706-1)
- 710785 Gentoo Linux Netatalk Multiple Vulnerabilities including root Remote Code Execution (RCE) (GLSA 202311-02)
- 755094 SUSE Enterprise Linux Security Update for netatalk (SUSE-SU-2023:4084-1)