Debian 9905 Published by

A netatalk security update has been released for Debian GNU/Linux 10 LTS to address multiple security vulnerabilities.



DLA 3426-1: netatalk security update


-------------------------------------------------------------------------
Debian LTS Advisory DLA-3426-1 debian-lts@lists.debian.org
  https://www.debian.org/lts/security/ Markus Koschany
May 17, 2023   https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package : netatalk
Version : 3.1.12~ds-3+deb10u1
CVE ID : CVE-2021-31439 CVE-2022-0194 CVE-2022-23121 CVE-2022-23122
CVE-2022-23123 CVE-2022-23124 CVE-2022-23125 CVE-2022-43634
CVE-2022-45188
Debian Bug : 1034170 1024021

Multiple security vulnerabilities have been discovered in netatalk, the
Apple Filing Protocol service, which allow remote attackers to disclose
sensitive information, cause a denial of service or execute arbitrary code.

For Debian 10 buster, these problems have been fixed in version
3.1.12~ds-3+deb10u1.

We recommend that you upgrade your netatalk packages.

For the detailed security status of netatalk please refer to
its security tracker page at:
  https://security-tracker.debian.org/tracker/netatalk

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at:   https://wiki.debian.org/LTS