Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check the return value of seteuid(), which may allow a remote authenticated attacker to retain elevated privileges under error conditions.
Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check the return value of seteuid(), which may allow a remote authenticated attacker to retain elevated privileges under error conditions.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 50.00 |
| Exploitation signal(No additional exploitation signal) | ×1.00 |
| VPI | 50.00 |
VPI formula vpi-v1