Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-38439


Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN] to '\0' in FPLoginExt in login in etc/uams/uams_pam.c. 2.4.1 and 3.1.19 are also fixed versions.


Published

2024-06-16T13:15:53.030

Last Modified

2024-11-21T09:25:51.770

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-787
  • Type: Secondary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application netatalk netatalk < 2.4.1 Yes
Application netatalk netatalk < 3.1.19 Yes
Application netatalk netatalk 3.2.0 Yes

References