Back

CVE-2018-1160

CRITICAL

Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.

Published: Dec 20, 2018 Modified: Jun 17, 2026
CWE-787 CWE-787 CWE-787

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (8)

Vendor Product Version
netatalk netatalk * < 3.1.12
synology router_manager * ≥ 1.2 < 1.2-7742-5
synology skynas -
synology diskstation_manager * ≥ 5.2 < 5.2-5967-9
synology diskstation_manager * ≥ 6.1 < 6.1.7-15284-3
synology diskstation_manager * ≥ 6.2 < 6.2.1-23824-4
synology vs960hd_firmware -
debian debian_linux 9.0

GitHub Security Advisory GHSA-j675-7hvj-qfw5

Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 86.54%

Top 0% most likely to be exploited

Threat Score 75.2 / 100

Data Sources

NVD EPSS GitHub