Bug 1226431 (CVE-2024-38441)

Summary: VUL-0: CVE-2024-38441: netatalk: off-by-one error resultant in a heap-based buffer overflow because of setting ibuf[len] to '\0' in FPMapName in afp_mapname in etc/afp/directory.c.
Product: [Novell Products] SUSE Security Incidents Reporter: SMASH SMASH <smash_bz>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P2 - High CC: andrea.mattiazzo
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/411056/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-38441:7.3:(AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description SMASH SMASH 2024-06-17 10:46:42 UTC
Netatalk 3.2.0 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\0' in FPMapName in afp_mapname in etc/afp/directory.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-38441
https://www.cve.org/CVERecord?id=CVE-2024-38441
https://github.com/Netatalk/netatalk/issues/1098
Comment 2 Petr Gajdos 2024-06-24 08:18:30 UTC
https://security-tracker.debian.org/tracker/CVE-2024-38441
MITRE pinged for clarification or rejection by Debian
Comment 4 Andrea Mattiazzo 2024-07-01 15:07:26 UTC
https://netatalk.io/security/CVE-2024-38441

Tracking as affected:
- SUSE:SLE-12:Update/netatalk
Comment 5 Petr Gajdos 2024-07-02 12:51:27 UTC
Submitted for 12/netatalk.

I believe all fixed.
Comment 7 Maintenance Automation 2024-07-04 16:30:10 UTC
SUSE-SU-2024:2301-1: An update that solves three vulnerabilities can now be installed.

Category: security (important)
Bug References: 1226429, 1226430, 1226431
CVE References: CVE-2024-38439, CVE-2024-38440, CVE-2024-38441
Maintenance Incident: [SUSE:Maintenance:34547](https://smelt.suse.de/incident/34547/)
Sources used:
SUSE Linux Enterprise Software Development Kit 12 SP5 (src):
 netatalk-3.1.18-3.25.1
SUSE Linux Enterprise Workstation Extension 12 12-SP5 (src):
 netatalk-3.1.18-3.25.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Andrea Mattiazzo 2024-07-08 09:22:37 UTC
All done, closing.