CVE-2018-1160: Critical severity Netatalk Netatalk vulnerability
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsiopensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1160?
CVE-2018-1160 is a vulnerability in Netatalk before version 3.1.12 that allows remote unauthenticated attackers to execute arbitrary code.
How severe is CVE-2018-1160?
CVE-2018-1160 has a severity rating of 9.8 (critical).
What is the affected software for CVE-2018-1160?
The affected software for CVE-2018-1160 includes Netatalk versions up to and including 3.1.12, Synology DiskStation Manager versions up to 5.2-5967-9, Synology Router Manager versions up to 1.2-7742-5, Synology Skynas, and Synology Vs960hd Firmware.
How can I fix CVE-2018-1160?
To fix CVE-2018-1160, update Netatalk to version 3.1.12 or later.
Where can I find more information about CVE-2018-1160?
You can find more information about CVE-2018-1160 on the Debian security tracker and MITRE CVE database websites.