ZeroHour

CVE-2018-1160

PoC ×5
CVSS 3.1
9.8 critical
EPSS
87%p100
Published
()
Modified
Description

Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.

Vendors
netatalksynologydebian
Products
netatalk, router manager, skynas, diskstation manager, vs960hd firmware, debian linux
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news