← Back to browse · API

CVE-2018-1160

Severity
CRITICAL
CVSS
9.8
EPSS
0.86539
Risk score
69.49
CISA KEV
No
PoC
No
Published
2018-12-20
Modified
2026-02-13
First seen
2026-08-07
Aliases
EUVD-2018-11798, GHSA-J675-7HVJ-QFW5
Products
Netatalk:Netatalk Before 3.1.12
Sources
euvd EUVD-2018-11798

Description

Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.

References