Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade netatalk | Aug 22, 2024 | Nov 12, 2022 |
| Debian | — | Upgrade netatalk | May 18, 2023 | Nov 12, 2022 |
| Gentoo Linux | — | Upgrade net-fs/netatalk. | Nov 2, 2023 | Nov 12, 2022 |
| Suse | — | Upgrade netatalk-develUpgrade netatalkUpgrade libatalk12 | Dec 9, 2022 | Nov 12, 2022 |
| Ubuntu | — | Upgrade netatalkUpgrade netatalk (Ubuntu Pro) | Jun 9, 2023 | Nov 12, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub