CVE-2022-43634 is a critical remote code execution vulnerability affecting Netatalk, specifically within the dsi_writeinit function. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges due to improper validation of user-supplied data length before a heap-based buffer copy. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk, requiring no authentication or user interaction for exploitation. While no public exploit code or active exploitation is currently reported, its high FAUCET Risk Score and media coverage indicate significant potential impact and community awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1.13CPE matchmatch criteria | cpe:2.3:a:netatalk:netatalk:3.1.13:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.