漏洞描述
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.debian.orghttps://www.debian.org/security/2018/dsa-4356↗www.synology.comhttps://www.synology.com/security/advisory/Synology_SA_18_62↗www.tenable.comhttps://www.tenable.com/security/research/tra-2018-48↗attachments.samba.orghttps://attachments.samba.org/attachment.cgi?id=14735↗packetstormsecurity.comhttp://packetstormsecurity.com/files/152440/QNAP-Netatalk-Authentication-Bypass.html↗netatalk.sourceforge.nethttp://netatalk.sourceforge.net/3.1/ReleaseNotes3.1.12.html↗www.securityfocus.comhttp://www.securityfocus.com/bid/106301↗