CRITICAL
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c
Published Dec 20, 2018
9.8
CRITICALCVSS 3.1
EPSS 86.54%
Description
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.
Affected products
-
- Version Before 3.1.12StatusaffectedConstraints-
- Version
Configuration 2
OR
- ≥ 1.2 · < 1.2-7742-5
- n/a
- ≥ 5.2 · < 5.2-5967-9
- ≥ 6.1 · < 6.1.7-15284-3
- ≥ 6.2 · < 6.2.1-23824-4
Configuration 3
AND
- n/a
Configuration 4
- 9.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://netatalk.sourceforge.net/3.1/ReleaseNotes3.1.12.html x_refsource_CONFIRMRelease Notes
- http://packetstormsecurity.com/files/152440/QNAP-Netatalk-Authentication-Bypass.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/106301 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://attachments.samba.org/attachment.cgi?id=14735 x_refsource_MISCThird Party Advisory
- https://github.com/tenable/poc/tree/master/netatalk/cve_2018_1160/ x_refsource_MISCRelease NotesThird Party Advisory
- https://www.debian.org/security/2018/dsa-4356 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.exploit-db.com/exploits/46034/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46048/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46675/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.synology.com/security/advisory/Synology_SA_18_62 x_refsource_CONFIRMThird Party Advisory
- https://www.tenable.com/security/research/tra-2018-48 x_refsource_MISCExploitRelease NotesThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner tenable
Published Dec 20, 2018
Updated Feb 13, 2026
Reserved Dec 5, 2017
Link CVE-2018-1160
CISA Vulnrichment
Updated Feb 13, 2026