USN-6552-1: Netatalk vulnerability
12 December 2023
Netatalk could be made to crash or run programs if it received specially crafted network traffic.
Releases
Packages
- netatalk - Apple Filing Protocol service
Details
Florent Saudel and Arnaud Gatignol discovered that Netatalk incorrectly
handled certain specially crafted Spotlight requests. A remote attacker could
possibly use this issue to cause heap corruption and execute arbitrary code.
(CVE-2023-42464)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 23.04
Ubuntu 22.04
Ubuntu 20.04
In general, a standard system update will make all the necessary changes.