Impact
The vulnerability is a heap out-of-bounds read that occurs during Spotlight RPC unmarshalling. This flaw allows bytes beyond the intended buffer to be read, enabling a remote authenticated attacker to obtain sensitive information or cause a minor service disruption. The weakness is an out-of-bounds read, classified as CWE-125.
Affected Systems
Netatalk, versions 3.1.0 through 4.4.2, are affected. The vulnerability is present in the Netatalk server component that handles Spotlight RPC requests.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact with potential confidentiality compromise. EPSS data is not available, so the current likelihood of exploitation remains unknown. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could send crafted Spotlight RPC messages over the network to trigger the out-of-bounds read, leading to data leakage.
OpenCVE Enrichment
Debian DSA