FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-5718

This CVE name corresponds to:

Entered Topic
2009-03-18 netatalk -- arbitrary command execution in papd daemon

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-5718
Phase Assigned(20081226)

Description

The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute arbitrary commands via shell metacharacters in a print request, as demonstrated using a crafted Title.

References

Source Reference
CONFIRM http://sourceforge.net/project/shownotes.php?release_id=648189
MLIST [oss-security] 20090114 update on CVE-2008-5718
DEBIAN DSA-1705
FEDORA FEDORA-2009-3064
FEDORA FEDORA-2009-3069
SUSE SUSE-SR:2009:004
BID 32925
OSVDB 50824
SECUNIA 33227
SECUNIA 33548
SECUNIA 34484