Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
{ "binaries": [ { "binary_version": "2.2.2-1ubuntu2.2+esm1", "binary_name": "netatalk" } ], "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro" }
{ "binaries": [ { "binary_version": "2.2.5-1ubuntu0.2+esm1", "binary_name": "netatalk" } ], "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro" }
{ "binaries": [ { "binary_version": "2.2.6-1ubuntu0.18.04.2+esm1", "binary_name": "netatalk" } ], "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro" }
{ "binaries": [ { "binary_version": "3.1.12~ds-4ubuntu0.20.04.1", "binary_name": "netatalk" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "3.1.12~ds-9ubuntu0.22.04.1", "binary_name": "netatalk" } ], "availability": "No subscription required" }