10

CVE-2018-1160

Exploit

Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NetatalkNetatalk Version < 3.1.12
SynologyRouter Manager Version >= 1.2 < 1.2-7742-5
SynologySkynas Version-
SynologyDiskstation Manager Version >= 5.2 < 5.2-5967-9
SynologyDiskstation Manager Version >= 6.1 < 6.1.7-15284-3
SynologyDiskstation Manager Version >= 6.2 < 6.2.1-23824-4
SynologyVs960hd Firmware Version-
   SynologyVs960hd Version-
DebianDebian Linux Version9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 88.81% 0.995
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.