PT-2024-4334 · Netatalk+4 · Netatalk+4

Flysoar

·

Published

2024-06-16

·

Updated

2025-03-12

·

CVE-2024-38440

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Netatalk versions prior to 3.2.1 Netatalk version 3.2.0
Description The issue arises due to a lack of validation for the length field after parsing user-provided data, leading to an out-of-bounds heap write of one byte, potentially causing a Denial of Service (DoS) under certain heap layouts or with ASAN enabled. The vulnerability is located in the FPLoginExt operation of Netatalk, in the BN bin2bn function found in etc/uams/uams dhx pam.c.
Recommendations For Netatalk versions prior to 3.2.1, update to version 3.2.1 or later to resolve the issue. For Netatalk version 3.2.0, update to version 3.2.1 or later to resolve the issue. As a temporary workaround, consider disabling the FPLoginExt operation in Netatalk until a patch is available. Restrict access to the BN bin2bn function in etc/uams/uams dhx pam.c to minimize the risk of exploitation.

Fix

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10064
ALT-PU-2024-10857
ALT-PU-2024-17688
BDU:2024-04823
CVE-2024-38440
DLA-3968-1
GHSA-MXX4-9FHM-R3W5
MGASA-2024-0259
SUSE-SU-2024:2301-1
USN-7347-1

Affected Products

Alt Linux
Linuxmint
Netatalk
Suse
Ubuntu