{"id":"MGASA-2024-0259","summary":"Updated netatalk packages fix security vulnerabilities","details":"Netatalk before 3.2.1 has an off-by-one error and resultant heap-based\nbuffer overflow because of setting ibuf[PASSWDLEN] to '\\0' in FPLoginExt\nin login in etc/uams/uams_pam.c. (CVE-2024-38439)\nNetatalk before 3.2.1 has an off-by-one error, and resultant heap-based\nbuffer overflow and segmentation violation, because of incorrectly using\nFPLoginExt in BN_bin2bn in etc/uams/uams_dhx_pam.c. The original issue\n1097 report stated: 'The latest version of Netatalk (v3.2.0) contains a\nsecurity vulnerability. This vulnerability arises due to a lack of\nvalidation for the length field after parsing user-provided data,\nleading to an out-of-bounds heap write of one byte (\\0). Under specific\nconfigurations, this can result in reading metadata of the next heap\nblock, potentially causing a Denial of Service (DoS) under certain heap\nlayouts or with ASAN enabled. ... The vulnerability is located in the\nFPLoginExt operation of Netatalk, in the BN_bin2bn function found in\n/etc/uams/uams_dhx_pam.c ... if (!(bn = BN_bin2bn((unsigned char *)ibuf,\nKEYSIZE, NULL))) ... threads ... [#0] Id 1, Name: \"afpd\", stopped\n0x7ffff4304e58 in ?? (), reason: SIGSEGV ... [#0] 0x7ffff4304e58 mov\nBYTE PTR [r14+0x8], 0x0 ... mov rdx, QWORD PTR [rsp+0x18] ...\nafp_login_ext(obj=\u003coptimized out\u003e, ibuf=0x62d000010424 \"\",\nibuflen=0xffffffffffff0015, rbuf=\u003coptimized out\u003e, rbuflen=\u003coptimized\nout\u003e) ... afp_over_dsi(obj=0x5555556154c0 \u003cobj\u003e).'. (CVE-2024-38440)\nNetatalk before 3.2.1 has an off-by-one error and resultant heap-based\nbuffer overflow because of setting ibuf[len] to '\\0' in FPMapName in\nafp_mapname in etc/afpd/directory.c. (CVE-2024-38441)\n","modified":"2026-04-16T04:44:31.918539094Z","published":"2024-07-10T18:01:45Z","upstream":["CVE-2024-38439","CVE-2024-38440","CVE-2024-38441"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2024-0259.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=33381"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UM3M423DHSUBERDIYCFHYY6XF2CAAMA2/"}],"affected":[{"package":{"name":"netatalk","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/netatalk?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.14-2.4.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0259.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}