CVE-2018-1160: Debian Linux
Critical severity, CVSS 9.8. EPSS: 86.5% chance of exploitation in the next 30 days.
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.
Affected products
- Debian Debian Linux: version 9.0 only
- Netatalk Netatalk: before 3.1.12 (fixed in 3.1.12)
- Synology Diskstation Manager: from 5.2, before 5.2-5967-9 (fixed in 5.2-5967-9); from 6.1, before 6.1.7-15284-3 (fixed in 6.1.7-15284-3); from 6.2, before 6.2.1-23824-4 (fixed in 6.2.1-23824-4)
- Synology Router Manager: from 1.2, before 1.2-7742-5 (fixed in 1.2-7742-5)
- Synology Skynas: affected versions not specified
- Synology VS960HD Firmware: affected versions not specified
Published 2018-12-20. Last modified 2026-06-17.