PT-2024-28004 · Netatalk+4 · Netatalk+4

Flysoar

·

Published

2024-06-16

·

Updated

2025-03-12

·

CVE-2024-38441

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netatalk versions prior to 3.2.1 Netatalk versions prior to 2.4.1 Netatalk versions prior to 3.1.19
Description The issue is caused by an off-by-one error and resultant heap-based buffer overflow in the FPMapName function in afp mapname in etc/afpd/directory.c, due to setting ibuf[len] to '0'.
Recommendations For versions prior to 3.2.1, update to version 3.2.1 or later. For versions prior to 2.4.1, update to version 2.4.1 or later. For versions prior to 3.1.19, update to version 3.1.19 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10064
ALT-PU-2024-10857
ALT-PU-2024-17688
CVE-2024-38441
DLA-3968-1
GHSA-MJ6V-CR68-MJ9Q
MGASA-2024-0259
SUSE-SU-2024:2301-1
USN-7347-1

Affected Products

Alt Linux
Linuxmint
Netatalk
Suse
Ubuntu