PT-2024-28003 · Netatalk+4 · Netatalk+4

Flysoar

·

Published

2024-06-16

·

Updated

2025-03-12

·

CVE-2024-38439

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netatalk versions prior to 3.2.1 Netatalk version 3.2.0
Description The issue is caused by an off-by-one error and resultant heap-based buffer overflow in the FPLoginExt function in the login module of etc/uams/uams pam.c. This occurs when setting ibuf[PASSWDLEN] to '0'.
Recommendations For Netatalk version 3.2.0, update to version 3.2.1 or later to resolve the issue. For versions prior to 3.2.1, update to version 3.2.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the FPLoginExt function in the login module until a patch is available.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10064
ALT-PU-2024-10857
ALT-PU-2024-17688
CVE-2024-38439
DLA-3968-1
GHSA-8R68-857C-4RQC
MGASA-2024-0259
SUSE-SU-2024:2301-1
SUSE-SU-2024_2301-1
USN-7347-1

Affected Products

Alt Linux
Linuxmint
Netatalk
Suse
Ubuntu