CVE-2008-5718

UnknownEPSS 4.53%

Last modified

CVE-2008-5718 is a vulnerability of currently unknown severity. The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute arbitrary commands via shell metacharacters in a print request, as demonstrated using a crafted Title.. EPSS estimates a 4.53% chance of exploitation in the next 30 days.

Description

The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute arbitrary commands via shell metacharacters in a print request, as demonstrated using a crafted Title.

Metrics

EPSS Probability
4.53%

90.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
NetatalkNetatalk<= 2.0.3
NetatalkNetatalk1.4.99-0.20000927
NetatalkNetatalk1.4.99-0.20001108
NetatalkNetatalk1.5Rc1
NetatalkNetatalk1.5.0
NetatalkNetatalk1.5.1
NetatalkNetatalk1.5.1.1
NetatalkNetatalk1.5.2
NetatalkNetatalk1.5.3.1
NetatalkNetatalk1.5.5
NetatalkNetatalk1.5pre3
NetatalkNetatalk1.5pre4
NetatalkNetatalk1.5pre5
NetatalkNetatalk1.5pre6
NetatalkNetatalk1.5pre7
NetatalkNetatalk1.5pre8
NetatalkNetatalk1.6.0
NetatalkNetatalk1.6.1
NetatalkNetatalk1.6.2
NetatalkNetatalk1.6.3
NetatalkNetatalk1.6.4
NetatalkNetatalk1.6.4a
NetatalkNetatalk2.0Alpha1
NetatalkNetatalk2.0.0
NetatalkNetatalk2.0.1
NetatalkNetatalk2.0.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2008-5718?
The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute arbitrary commands via shell metacharacters in a print request, as demonstrated using a crafted Title.
How severe is CVE-2008-5718?
Severity scoring for CVE-2008-5718 is pending analysis. The EPSS model estimates a 4.53% probability of exploitation in the next 30 days.
How do I fix CVE-2008-5718?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2008-5718?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST