CVE-2018-1160

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
20/12/2018
Last modified:
14/01/2025

Description

Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netatalk:netatalk:*:*:*:*:*:*:*:* 3.1.12 (excluding)
cpe:2.3:a:synology:router_manager:*:*:*:*:*:*:*:* 1.2 (including) 1.2-7742-5 (excluding)
cpe:2.3:a:synology:skynas:-:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* 5.2 (including) 5.2-5967-9 (excluding)
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* 6.1 (including) 6.1.7-15284-3 (excluding)
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* 6.2 (including) 6.2.1-23824-4 (excluding)
cpe:2.3:o:synology:vs960hd_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:synology:vs960hd:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*