← All CVEs

CVE-2018-1160

critical · 9.8

Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.

9.8
CVSS
86.5%
EPSS (exploit prob.)
100th
EPSS percentile
2018-12-20
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-787

Affected products

VendorProductAffected versions
netatalknetatalk< 3.1.12
synologyrouter_manager>= 1.2, < 1.2-7742-5
synologyskynasall versions
synologydiskstation_manager>= 5.2, < 5.2-5967-9
synologydiskstation_manager>= 6.1, < 6.1.7-15284-3
synologydiskstation_manager>= 6.2, < 6.2.1-23824-4
synologyvs960hd_firmwareall versions
synologyvs960hdall versions
debiandebian_linux9.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-1160