Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 9: 2024-0259 Critical: Netatalk Buffer Overflow and DoS Threats

mageia
Calendar Grey July 10, 2024
Dist Mageia Esm H88
Netatalk 3.2.1 security patch addresses major vulnerabilities, including buffer overflow risks and possible Denial of Service attacks.
Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN] to '\0' in FPLoginExt in login in etc/uams/uams_pam.c

Summary

Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN] to '\0' in FPLoginExt in login in etc/uams/uams_pam.c. (CVE-2024-38439) Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, because of incorrectly using FPLoginExt in BN_bin2bn in etc/uams/uams_dhx_pam.c. The original issue 1097 report stated: 'The latest version of Netatalk (v3.2.0) contains a security vulnerability. This vulnerability arises due to a lack of validation for the length field after parsing user-provided data, leading to an out-of-bounds heap write of one byte (\0). Under specific configurations, this can result in reading metadata of the next heap block, potentially causing a Denial of Service (DoS) under certain heap layouts or with ASAN enabled. ... The vulnerability is located in the FPLoginExt operation of Netatalk, in the BN_bin2bn function found in /etc/uams/uams_dhx_pam.c ... i...

References

- https://bugs.mageia.org/show_bug.cgi?id=33381

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UM3M423DHSUBERDIYCFHYY6XF2CAAMA2/

- https://www.cve.org/CVERecord?id=CVE-2024-38439

- https://www.cve.org/CVERecord?id=CVE-2024-38440

- https://www.cve.org/CVERecord?id=CVE-2024-38441

Resolution

SRPMS

- 9/core/netatalk-3.1.14-2.4.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 10 Jul 2024
URL: https://advisories.mageia.org/MGASA-2024-0259.html
Type: security
CVE: CVE-2024-38439, CVE-2024-38440, CVE-2024-38441

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here