Bugs fixes in "netatalk"
| Origin | Bug number | Title | Date fixed |
|---|---|---|---|
| CVE | CVE-2026-44068 | Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to | 2026-06-22 |
| CVE | CVE-2026-44066 | Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3.1.0 through 4.4.2 allow a remote authenticated attacker to ob | 2026-06-22 |
| CVE | CVE-2026-44057 | A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective | 2026-06-22 |
| CVE | CVE-2026-44068 | Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to | 2026-06-22 |
| CVE | CVE-2026-44066 | Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3.1.0 through 4.4.2 allow a remote authenticated attacker to ob | 2026-06-22 |
| CVE | CVE-2026-44057 | A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective | 2026-06-22 |
| CVE | CVE-2026-44064 | An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 allows an adjacent network attacker to obtain limited information or c | 2026-06-09 |
| CVE | CVE-2026-44062 | A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitr | 2026-06-09 |
| CVE | CVE-2026-44060 | An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a remote unauthenticated attacker to cause a denial of service via a c | 2026-06-09 |
| CVE | CVE-2026-44055 | A logic error involving bitwise OR operations in Netatalk 3.1.4 through 4.4.2 allows a remote authenticated attacker to inject OS commands and execut | 2026-06-09 |
| CVE | CVE-2026-44052 | Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an attacker with access to the log files t | 2026-06-09 |
| CVE | CVE-2026-44051 | An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read arbitrary files or overwrite | 2026-06-09 |
| CVE | CVE-2026-44050 | A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute | 2026-06-09 |
| CVE | CVE-2026-44049 | An out-of-bounds write due to improper null termination in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker t | 2026-06-09 |
| CVE | CVE-2026-44048 | A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to | 2026-06-09 |
| CVE | CVE-2026-44047 | An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorize | 2026-06-09 |
| CVE | CVE-2026-44064 | An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 allows an adjacent network attacker to obtain limited information or c | 2026-06-09 |
| CVE | CVE-2026-44062 | A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitr | 2026-06-09 |
| CVE | CVE-2026-44060 | An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a remote unauthenticated attacker to cause a denial of service via a c | 2026-06-09 |
| CVE | CVE-2026-44055 | A logic error involving bitwise OR operations in Netatalk 3.1.4 through 4.4.2 allows a remote authenticated attacker to inject OS commands and execut | 2026-06-09 |
About
-
Send Feedback to @ubuntu_updates