CVE-2024-38441

Name
CVE-2024-38441
Description
Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\0' in FPMapName in afp_mapname in etc/afpd/directory.c. 2.4.1 and 3.1.19 are also fixed versions.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://github.com/Netatalk/netatalk/issues/1098
cve@mitre.org https://github.com/Netatalk/netatalk/blob/90d91a9ac9a7d6132ab7620d31c8c23400949206/etc/afpd/directory.c#L2333
cve@mitre.org https://github.com/Netatalk/netatalk/security/advisories/GHSA-mj6v-cr68-mj9q
cve@mitre.org https://netatalk.io/security/CVE-2024-38441
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2024/11/msg00026.html

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
netatalk edge-community 3.1.19-r0 Alexander Rigbo <alex@dnb.nu> fixed
netatalk 3.22-community 3.1.19-r0 Alexander Rigbo <alex@dnb.nu> fixed
netatalk 3.21-community 3.1.19-r0 Alexander Rigbo <alex@dnb.nu> fixed
netatalk 3.20-community 3.1.19-r0 Alexander Rigbo <alex@dnb.nu> fixed