Out-of-bounds write in Netatalk - CVE-2018-1160

 

Out-of-bounds write in Netatalk - CVE-2018-1160

Published: December 21, 2018 / Updated: February 13, 2023


Vulnerability identifier: #VU16646
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1160
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error in dsi_opensess.c. A remote attacker can trigger an out-of-bounds write and crash the affected application or execute arbitrary code on the target system.


Affected software

Netatalk
WebSVN
netatalk (Debian package)
netatalk (Alpine package)
Slackware Linux
Opensuse
GS-AX3000
GT-AXE16000
GS-AX5400
GT6
TUF-AX5400
RT-AX82U
RT-AX86S
RT-AX86U
RT-AX86U PRO
ZenWiFi XT8_V2
ZenWiFi XT8
ZenWiFi XT9
GT-AX11000
GT-AX6000
GT-AXE11000 PRO
RT-AX58U
RT-AX3000
GT-AXE11000
TUF-AX6000
MySQL Server

How to mitigate CVE-2018-1160

Update to version 3.1.12.

Netatalk - addressed in versions 3.1.12, 2.2.7
netatalk (Debian package) - update to 2.2.5-2+deb9u1
netatalk (Alpine package) - update to 3.1.12-r0
GS-AX3000 - update to 1.4.8.3
GT-AXE16000 - update to 3.0.0.4.388.23012
GS-AX5400 - update to 3.0.0.4.388.23012
GT6 - update to 3.0.0.4.388.23145
TUF-AX5400 - update to 3.0.0.4.388.23285
RT-AX82U - update to 3.0.0.4.388.23285
RT-AX86S - update to 3.0.0.4.388.23285
RT-AX86U - update to 3.0.0.4.388.23285
RT-AX86U PRO - update to 3.0.0.4.388.23285
ZenWiFi XT8_V2 - update to 3.0.0.4.388.23285
ZenWiFi XT8 - update to 3.0.0.4.388.23285
ZenWiFi XT9 - update to 3.0.0.4.388.23285
GT-AX11000 - update to 3.0.0.4.388.23285
GT-AX6000 - update to 3.0.0.4.388.23285
GT-AXE11000 PRO - update to 3.0.0.4.388.23285
RT-AX58U - update to 3.0.0.4.388.23403
RT-AX3000 - update to 3.0.0.4.388.23403
GT-AXE11000 - update to 3.0.0.4.388.23482
TUF-AX6000 - update to 3.0.0.4.388.31927
MySQL Server - update to 5.6.21

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins