Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN] to '\0' in FPLoginExt in login in etc/uams/uams_pam.c. 2.4.1 and 3.1.19 are also fixed versions.
{
"versions": [
{
"introduced": "2.0.0"
},
{
"fixed": "2.4.1"
},
{
"introduced": "3.0.0"
},
{
"fixed": "3.1.19"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.0"
}
]
}