CRITICAL🇵🇱 Wersja polska

CVE-2024-38439

CVSS 9.8v3.1pub. 2024-06-16upd. 2025-11-03

Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN] to '\0' in FPLoginExt in login in etc/uams/uams_pam.c. 2.4.1 and 3.1.19 are also fixed versions.

🤖 AI Analysis
How it works

The vulnerability occurs in the FPLoginExt function in the file etc/uams/uams_pam.c, where improper null termination (zeroing) is assigned to the element ibuf[PASSWDLEN] — an index one position beyond the declared password buffer boundary. This is a classic off-by-one error that causes overwriting of an adjacent byte on the heap. A remote attacker, by sending a specially crafted login request, can cause controlled heap memory structure corruption.

Impact

A remote, unauthenticated attacker can achieve arbitrary code execution (RCE) on a vulnerable system with Netatalk process privileges, as well as compromise the confidentiality, integrity, and availability of data.

Mitigation & patch

Netatalk should be updated to version 3.2.1, 3.1.19, or 2.4.1 (depending on the branch in use). Patches are available in the project repository and are described in Security Advisory GHSA-8r68-857c-4rqc.

Who is affected

Netatalk in all versions before 3.2.1 (fixes were also introduced in versions 2.4.1 and 3.1.19)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Netatalk

    APP
    Netatalk
    3.2.02.0.0 – 2.4.1 (excl.)3.0.0 – 3.1.19 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2024-38441CRITICAL9.8PL ✓same product

Heap-based buffer overflow w Netatalk (off-by-one w FPMapName)

CVE-2023-42464CRITICAL9.8PL ✓same product

Type Confusion w Netatalk afpd — możliwe RCE przez Spotlight RPC

CVE-2022-43634CRITICAL9.8PL ✓same product

RCE bez uwierzytelnienia w Netatalk — błąd funkcji dsi_writeinit

CVE-2022-23121CRITICAL9.8PL ✓same product

Netatalk: RCE bez uwierzytelnienia przez błąd parsowania AppleDouble

CVE-2022-23122CRITICAL9.8PL ✓same product

RCE w Netatalk — stack-based buffer overflow w funkcji setfilparams