Bug 1205393 - (CVE-2022-45188) VUL-0: CVE-2022-45188: netatalk: heap-based buffer overflow in afp_getappl()
(CVE-2022-45188)
VUL-0: CVE-2022-45188: netatalk: heap-based buffer overflow in afp_getappl()
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/347771/
CVSSv3.1:SUSE:CVE-2022-45188:7.8:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-11-14 11:03 UTC by Carlos López
Modified: 2022-12-12 10:15 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carlos López 2022-11-14 11:03:12 UTC
CVE-2022-45188

Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting
in code execution via a crafted .appl file. This provides remote root access on
some platforms such as FreeBSD (used for TrueNAS).

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-45188
http://www.cvedetails.com/cve/CVE-2022-45188/
https://www.cve.org/CVERecord?id=CVE-2022-45188
https://rushbnt.github.io/bug%20analysis/netatalk-0day/
https://sourceforge.net/projects/netatalk/files/netatalk/
https://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.13.html
https://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.14.html
Comment 1 Carlos López 2022-11-14 11:16:20 UTC
Not fixed upstream yet it seems.

This affects SUSE:SLE-12:Update/netatalk AFAICT.
Comment 2 Petr Gajdos 2022-11-24 10:49:34 UTC
(In reply to Carlos López from comment #0)
> https://rushbnt.github.io/bug%20analysis/netatalk-0day/

"this is RCE vulnerability in FreeBSD and LPE in other OS"

> https://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.13.html
> https://netatalk.sourceforge.io/3.1/ReleaseNotes3.1.14.html

Note that 3.1.14 was not released, so this link is invalid.
Comment 9 Petr Gajdos 2022-11-29 15:03:31 UTC
Package submitted for 12/netatalk.
Comment 11 Swamp Workflow Management 2022-12-08 20:22:11 UTC
SUSE-SU-2022:4360-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1205393
CVE References: CVE-2022-45188
JIRA References: 
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP5 (src):    netatalk-3.1.0-3.11.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    netatalk-3.1.0-3.11.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Marcus Meissner 2022-12-12 10:15:16 UTC
done