CVE-2024-38439
Netatalk
CVE-2024-38439 is a critical heap-based buffer overflow vulnerability in Netatalk before version 3.2.1, stemming from an off-by-one error in the FPLoginExt function. This flaw, located within the login process in etc/uams/uams_pam.c, arises from incorrectly setting ibuf[PASSWDLEN] to '\0'. Although the CVSS score is a very high 9.8, SOCRadar's Vulnerability Risk Score (SVRS) is 34 indicating it may not be as actively exploited compared to other vulnerabilities with higher SVRS scores. Versions 2.4.1 and 3.1.19 are also patched versions. Successful exploitation could lead to remote code execution on affected systems. Despite being tagged as "In The Wild", the relatively low SVRS suggests the exploit may not be widespread. However, given the potential for significant impact, organizations using Netatalk should prioritize updating to a patched version to mitigate the security risk associated with this vulnerability.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.