CVE-2008-5718

NameCVE-2008-5718
SourceCVE (at NVD; RH)
DescriptionThe papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute arbitrary commands via shell metacharacters in a print request, as demonstrated using a crafted Title.
ReferencesDSA-1705-1, DTSA-183-1
NVD severityhigh
Debian Bugs510585
Debian/oldstablenot vulnerable
Debian/stablenot vulnerable
Debian/testingnot vulnerable
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
netatalk (PTS)etch, etch (security)2.0.3-4+etch2fixed
lenny, lenny (security)2.0.3-11+lenny1fixed
squeeze, sid2.0.5-3fixed

The next table lists affected binary packages.

Binary PackageReleaseVersionStatusArchitecures
netatalketch, etch (security)2.0.3-4+etch2fixedalpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
lenny2.0.3-11+lenny1fixedalpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
lenny (security)2.0.3-11+lenny1fixedalpha, amd64, arm, armel, hppa, ia64, mips, mipsel, powerpc, s390, sparc
sid2.0.5-3fixedalpha, amd64, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
squeeze2.0.5-3fixedamd64, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
netatalksource(unstable)2.0.4~beta2-1medium510585
netatalksourceetch2.0.3-4+etch1unknownDSA-1705-1
netatalksourcelenny2.0.3-11+lenny1unknownDTSA-183-1

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint