Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Netatalk versions 2.1.0 through 4.4.2 write LDAP authentication passwords to log files in cleartext, exposing valid directory credentials to anyone with log read access. Organizations running Netatalk for Apple Filing Protocol (AFP) file sharing on Linux or Unix systems are at risk of credential theft that could enable attackers to move laterally through Active Directory or LDAP environments. The exposure is credential theft via log file access, not remote code execution; the downstream impact on identity infrastructure can be significant.

Author

Tech Jacks Solutions