Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.
{ "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.2.5-1ubuntu0.2", "binary_name": "netatalk" }, { "binary_version": "2.2.5-1ubuntu0.2", "binary_name": "netatalk-dbg" }, { "binary_version": "2.2.5-1ubuntu0.2", "binary_name": "netatalk-dbgsym" } ], "availability": "No subscription required" }