Lucene search

K
cvelistTenableCVELIST:CVE-2018-1160
HistoryDec 20, 2018 - 9:00 p.m.

CVE-2018-1160

2018-12-2021:00:00
CWE-787
tenable
www.cve.org
5

AI Score

9.7

Confidence

High

EPSS

0.922

Percentile

99.0%

Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.

CNA Affected

[
  {
    "product": "Netatalk",
    "vendor": "Netatalk",
    "versions": [
      {
        "status": "affected",
        "version": "Before 3.1.12"
      }
    ]
  }
]