Описание
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.
Ссылки
- Release Notes
- ExploitThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- Third Party Advisory
- ExploitRelease NotesThird Party Advisory
- Release Notes
- ExploitThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 3.1.12 (исключая)
cpe:2.3:a:netatalk:netatalk:*:*:*:*:*:*:*:*
Конфигурация 2Версия от 1.2 (включая) до 1.2-7742-5 (исключая)Версия от 5.2 (включая) до 5.2-5967-9 (исключая)Версия от 6.1 (включая) до 6.1.7-15284-3 (исключая)Версия от 6.2 (включая) до 6.2.1-23824-4 (исключая)
Одно из
cpe:2.3:a:synology:router_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:synology:skynas:-:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*
Конфигурация 3
Одновременно
cpe:2.3:o:synology:vs960hd_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:synology:vs960hd:-:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.89732
Высокий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-787
CWE-787
Связанные уязвимости
CVSS3: 9.8
ubuntu
около 7 лет назад
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.
CVSS3: 9.8
debian
около 7 лет назад
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_ ...
EPSS
Процентиль: 100%
0.89732
Высокий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-787
CWE-787