Bugzilla – Bug 1214744
VUL-0: CVE-2023-42464: netatalk: afpd daemon vulnerable to type confusion
Last modified: 2024-07-02 13:20:07 UTC
https://kb.cert.org/vince/comm/case/1190/ Description: An authenticated attacker can trigger a type confusion through the call to the `openQueryWithParams:forContext:` Spotlight RPC routine. This vulnerability allows the attacker to fully control the value of a data pointer and potentially obtain Remote Code Execution.
CVE was assiogned
https://www.mail-archive.com/debian-bugs-dist@lists.debian.org/msg1931784.html https://github.com/Netatalk/netatalk/issues/486
Petr, could you resubmit with CVE added to the changes?
Done in rq#307918
SUSE-SU-2023:3779-1: An update that solves one vulnerability can now be installed. Category: security (important) Bug References: 1214744 CVE References: CVE-2023-42464 Sources used: SUSE Linux Enterprise Software Development Kit 12 SP5 (src): netatalk-3.1.0-3.19.1 SUSE Linux Enterprise Workstation Extension 12 12-SP5 (src): netatalk-3.1.0-3.19.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
done, closing