[Pkg-netatalk-devel] Bug#1036740: Fix for CVE-2022-23123 causes afpd segfault with valid metadata

Markus Koschany apo at debian.org
Thu May 25 11:37:20 BST 2023


Hello Daniel,

Am Donnerstag, dem 25.05.2023 um 08:02 +0200 schrieb Salvatore Bonaccorso:
> > 
> > These two commits in upstream addressed this:
> > https://github.com/Netatalk/netatalk/commit/9d0c21298363e8174cdfca657e66c4d10819507b
> > https://github.com/Netatalk/netatalk/commit/4140e5495bac42ecb9b11975229c81e84762cc98

Both patches have been backported to Buster. You can find them as CVE-2022-
23123_part3.patch and CVE-2022-23123_part4.patch.

Did we miss something else?

Regards,

Markus
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 963 bytes
Desc: This is a digitally signed message part
URL: <http://alioth-lists.debian.net/pipermail/pkg-netatalk-devel/attachments/20230525/3639b494/attachment.sig>


More information about the pkg-netatalk-devel mailing list