CVE-2021-31439
netatalk - security update
8.8
HIGH
CVSS 3.1
EPSS 1.0%
Description
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation Manager. Authentication is not required to exploit this vulnerablity. The specific flaw exists within the processing of DSI structures in Netatalk. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12326.
How to fix CVE-2021-31439
To remediate CVE-2021-31439, upgrade the affected package to a fixed version below.
- —upgrade to 3.1.12~ds-8+deb11u1 or later
- —upgrade to 3.1.12~ds-3+deb10u1 or later
- —upgrade to 3.1.12~ds-8+deb11u1 or later
Is CVE-2021-31439 being exploited?
Low — EPSS is 1.0%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 3.1.12~ds-8+deb11u1
- from 0, < 3.1.12~ds-3+deb10u1
- from 0, < 3.1.12~ds-8+deb11u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |