A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated privileges or cause a denial of service.
{
"binaries": [
{
"binary_name": "a2boot",
"binary_version": "4.2.3~ds-1"
},
{
"binary_name": "atalkd",
"binary_version": "4.2.3~ds-1"
},
{
"binary_name": "libatalk",
"binary_version": "4.2.3~ds-1"
},
{
"binary_name": "macipgw",
"binary_version": "4.2.3~ds-1"
},
{
"binary_name": "netatalk",
"binary_version": "4.2.3~ds-1"
},
{
"binary_name": "netatalk-tests",
"binary_version": "4.2.3~ds-1"
},
{
"binary_name": "netatalk-tools",
"binary_version": "4.2.3~ds-1"
},
{
"binary_name": "papd",
"binary_version": "4.2.3~ds-1"
},
{
"binary_name": "timelord",
"binary_version": "4.2.3~ds-1"
}
]
}{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "a2boot",
"binary_version": "4.2.3~ds-2.1ubuntu0.1"
},
{
"binary_name": "atalkd",
"binary_version": "4.2.3~ds-2.1ubuntu0.1"
},
{
"binary_name": "libatalk",
"binary_version": "4.2.3~ds-2.1ubuntu0.1"
},
{
"binary_name": "macipgw",
"binary_version": "4.2.3~ds-2.1ubuntu0.1"
},
{
"binary_name": "netatalk",
"binary_version": "4.2.3~ds-2.1ubuntu0.1"
},
{
"binary_name": "netatalk-tests",
"binary_version": "4.2.3~ds-2.1ubuntu0.1"
},
{
"binary_name": "netatalk-tools",
"binary_version": "4.2.3~ds-2.1ubuntu0.1"
},
{
"binary_name": "papd",
"binary_version": "4.2.3~ds-2.1ubuntu0.1"
},
{
"binary_name": "timelord",
"binary_version": "4.2.3~ds-2.1ubuntu0.1"
}
]
}