PT-2024-28003 · Netatalk+4 · Netatalk+4
Flysoar
·
Published
2024-06-16
·
Updated
2025-03-12
·
CVE-2024-38439
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Netatalk versions prior to 3.2.1
Netatalk version 3.2.0
Description
The issue is caused by an off-by-one error and resultant heap-based buffer overflow in the FPLoginExt function in the login module of etc/uams/uams pam.c. This occurs when setting
ibuf[PASSWDLEN] to '0'.Recommendations
For Netatalk version 3.2.0, update to version 3.2.1 or later to resolve the issue.
For versions prior to 3.2.1, update to version 3.2.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
FPLoginExt function in the login module until a patch is available.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Netatalk
Suse
Ubuntu