CVE-2018-1160
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to run any code they want on a system using Netatalk, which could lead to complete control over that system. It can be exploited remotely without needing to log in, as long as the attacker can send specially crafted data to the affected software.
Technical Description
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.
CVSS Vector Analysis
Vector String
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Dec 20, 2018
over 7 years ago
Last Modified
Feb 13, 2026
about 2 months ago
Vendor
netatalk
Product
netatalk