CVE-2018-1160

critical
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.

References

http://netatalk.sourceforge.net/3.1/ReleaseNotes3.1.12.html

http://packetstormsecurity.com/files/152440/QNAP-Netatalk-Authentication-Bypass.html

http://www.securityfocus.com/bid/106301

https://attachments.samba.org/attachment.cgi?id=14735

https://github.com/tenable/poc/tree/master/netatalk/cve_2018_1160/

https://www.debian.org/security/2018/dsa-4356

https://www.exploit-db.com/exploits/46034/

https://www.exploit-db.com/exploits/46048/

https://www.exploit-db.com/exploits/46675/

https://www.synology.com/security/advisory/Synology_SA_18_62

https://www.tenable.com/security/research/tra-2018-48

Details

Source: MITRE

Published: 2018-12-20

Updated: 2019-10-09

Type: CWE-787

Risk Information

CVSS v2

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 3.9

Severity: CRITICAL

Tenable Plugins

View all (6 total)

IDNameProductFamilySeverity
125935FreeBSD : netatalk3 -- remote code execution vulnerability (9c9023ff-9057-11e9-b764-00505632d232)NessusFreeBSD Local Security Checks
critical
119946openSUSE Security Update : netatalk (openSUSE-2018-1614)NessusSuSE Local Security Checks
critical
119870SUSE SLED12 Security Update : netatalk (SUSE-SU-2018:4217-1)NessusSuSE Local Security Checks
critical
119853Slackware 14.0 / 14.1 / 14.2 / current : netatalk (SSA:2018-355-01)NessusSlackware Local Security Checks
critical
119817Debian DSA-4356-1 : netatalk - security updateNessusDebian Local Security Checks
critical
119780Netatalk OpenSession Remote Code ExecutionNessusGain a shell remotely
critical