9.3

CVE-2008-5718

The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute arbitrary commands via shell metacharacters in a print request, as demonstrated using a crafted Title.

Data is provided by the National Vulnerability Database (NVD)
NetatalkNetatalk Version <= 2.0.3
NetatalkNetatalk Version1.4.99-0.20000927
NetatalkNetatalk Version1.4.99-0.20001108
NetatalkNetatalk Version1.5 Updaterc1
NetatalkNetatalk Version1.5 Updaterc2
NetatalkNetatalk Version1.5.0
NetatalkNetatalk Version1.5.1
NetatalkNetatalk Version1.5.1.1
NetatalkNetatalk Version1.5.2
NetatalkNetatalk Version1.5.3.1
NetatalkNetatalk Version1.5.5
NetatalkNetatalk Version1.5pre3
NetatalkNetatalk Version1.5pre4
NetatalkNetatalk Version1.5pre5
NetatalkNetatalk Version1.5pre6
NetatalkNetatalk Version1.5pre7
NetatalkNetatalk Version1.5pre8
NetatalkNetatalk Version1.6.0
NetatalkNetatalk Version1.6.1
NetatalkNetatalk Version1.6.2
NetatalkNetatalk Version1.6.3
NetatalkNetatalk Version1.6.4
NetatalkNetatalk Version1.6.4a
NetatalkNetatalk Version2.0 Updatealpha1
NetatalkNetatalk Version2.0 Updatealpha2
NetatalkNetatalk Version2.0 Updatebeta1
NetatalkNetatalk Version2.0 Updatebeta2
NetatalkNetatalk Version2.0 Updaterc1
NetatalkNetatalk Version2.0 Updaterc2
NetatalkNetatalk Version2.0.0
NetatalkNetatalk Version2.0.1
NetatalkNetatalk Version2.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.82% 0.821
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.