CVE-2008-5718

The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute arbitrary commands via shell metacharacters in a print request, as demonstrated using a crafted Title.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
VendorProductVersion
netatalknetatalk
𝑥
≤ 2.0.3
netatalknetatalk
1.4.99-0.20000927
netatalknetatalk
1.4.99-0.20001108
netatalknetatalk
1.5:rc1
netatalknetatalk
1.5:rc2
netatalknetatalk
1.5.0
netatalknetatalk
1.5.1
netatalknetatalk
1.5.1.1
netatalknetatalk
1.5.2
netatalknetatalk
1.5.3.1
netatalknetatalk
1.5.5
netatalknetatalk
1.5pre3:pre3
netatalknetatalk
1.5pre4:pre4
netatalknetatalk
1.5pre5:pre5
netatalknetatalk
1.5pre6:pre6
netatalknetatalk
1.5pre7:pre7
netatalknetatalk
1.5pre8:pre8
netatalknetatalk
1.6.0
netatalknetatalk
1.6.1
netatalknetatalk
1.6.2
netatalknetatalk
1.6.3
netatalknetatalk
1.6.4
netatalknetatalk
1.6.4a:a
netatalknetatalk
2.0:alpha1
netatalknetatalk
2.0:alpha2
netatalknetatalk
2.0:beta1
netatalknetatalk
2.0:beta2
netatalknetatalk
2.0:rc1
netatalknetatalk
2.0:rc2
netatalknetatalk
2.0.0
netatalknetatalk
2.0.1
netatalknetatalk
2.0.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
netatalk
bullseye (security)
3.1.12~ds-8+deb11u1
fixed
bullseye
3.1.12~ds-8+deb11u1
fixed
sid
4.0.3~ds-2
fixed
trixie
4.0.3~ds-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
netatalk
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
not-affected
intrepid
ignored
hardy
ignored
gutsy
ignored
dapper
ignored