Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.
2018-12-20T21:29:00.477
2025-01-14T19:29:55.853
Modified
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | netatalk | netatalk | < 3.1.12 | Yes |
Application | synology | router_manager | < 1.2-7742-5 | Yes |
Application | synology | skynas | - | Yes |
Operating System | synology | diskstation_manager | < 5.2-5967-9 | Yes |
Operating System | synology | diskstation_manager | < 6.1.7-15284-3 | Yes |
Operating System | synology | diskstation_manager | < 6.2.1-23824-4 | Yes |
Operating System | synology | vs960hd_firmware | - | Yes |
Hardware | synology | vs960hd | - | No |
Operating System | debian | debian_linux | 9.0 | Yes |