USN-6552-1: Netatalk vulnerability
Florent Saudel and Arnaud Gatignol discovered that Netatalk incorrectly handled certain specially crafted Spotlight requests. A remote attacker could possibly use this issue to cause heap corruption and execute arbitrary code. (CVE-2023-42464)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6552-1?
The severity of USN-6552-1 is critical due to the potential for remote code execution.
How do I fix USN-6552-1?
To fix USN-6552-1, you need to upgrade Netatalk to the patched versions 3.1.14~ds-1ubuntu0.1, 3.1.12~ds-9ubuntu0.22.04.3, or 3.1.12~ds-4ubuntu0.20.04.3 depending on your Ubuntu version.
Which versions of Ubuntu are affected by USN-6552-1?
USN-6552-1 affects Ubuntu versions 20.04, 22.04, and 23.04 with specific vulnerable versions of Netatalk.
What should I do if I cannot upgrade due to compatibility issues related to USN-6552-1?
If you cannot upgrade, consider applying mitigating controls such as firewall rules to limit exposure to vulnerable services until you can upgrade.
Is remote access required for exploiting the USN-6552-1 vulnerability?
Yes, a remote attacker can exploit the USN-6552-1 vulnerability without physical access to the system.