Advisories ยป MGASA-2023-0027

Updated netatalk packages fix security vulnerability

Publication date: 07 Feb 2023
Modification date: 06 Feb 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-31439 , CVE-2022-0194 , CVE-2022-23121 , CVE-2022-23122 , CVE-2022-23123 , CVE-2022-23124 , CVE-2022-23125 , CVE-2022-45188

Description

Heap overflow leading to arbitrary code execution. (CVE-2021-31439)
Buffer overflow leading to remote code execution (CVE-2022-0194)
Improper length validation leading to remote code execution
(CVE-2022-23121)
Buffer overflow leading to remote code execution (CVE-2022-23122)
Out-of-bounds read leading to information disclosure (CVE-2022-23123)
Out-of-bounds read leading to information disclosure (CVE-2022-23124)
Improper length validation leading to remote code execution
(CVE-2022-23125)
Heap-based buffer overflow in afp_getappl resulting in code execution via
a crafted .appl file (CVE-2022-45188)
                

References

SRPMS

8/core