20180316 DSA-2018-037: Dell EMC NetWorker Buffer Overflow Vulnerabilitymailing list
http://seclists.org/fulldisclosure/2018/Mar/43 CVE-2018-1218
HIGH
Dell EMC NetWorker - Denial of Service
Record summary
CVE-2018-1218 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the 'nsrd' daemon causes a buffer overflow condition when handling certain messages. A remote unauthenticated attacker could potentially exploit this vulnerability to cause a denial of service to the users of NetWorker systems.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Dell EMC NetWorkerBrowse Dell EMC / Dell EMC NetWorker | CVE List | prior to 9.2.1.1 | affected |
| prior to 9.1.1.6 | affected | ||
| 9.0.x | affected | ||
| prior to 8.2.4.11 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBDell EMC NetWorker - Denial of ServiceExploitDB exploitby Marek CybulNot analyzed1 file
References
41040546vdb entry
http://www.securitytracker.com/id/1040546 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-1218 44332exploit
https://www.exploit-db.com/exploits/44332