Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "high", "binaries": [ { "binary_version": "2.2.2-1ubuntu2.2+esm1", "binary_name": "netatalk" }, { "binary_version": "2.2.2-1ubuntu2.2+esm1", "binary_name": "netatalk-dbgsym" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "high", "binaries": [ { "binary_version": "2.2.5-1ubuntu0.2+esm1", "binary_name": "netatalk" }, { "binary_version": "2.2.5-1ubuntu0.2+esm1", "binary_name": "netatalk-dbg" }, { "binary_version": "2.2.5-1ubuntu0.2+esm1", "binary_name": "netatalk-dbgsym" } ] }