Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-38441


Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\0' in FPMapName in afp_mapname in etc/afpd/directory.c. 2.4.1 and 3.1.19 are also fixed versions.


Published

2024-06-16T13:15:53.230

Last Modified

2025-05-01T19:42:41.313

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-193

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application netatalk netatalk < 2.4.1 Yes
Application netatalk netatalk < 3.1.19 Yes
Application netatalk netatalk 3.2.0 Yes

References