{"affected":[{"ecosystem_specific":{"binaries":[{"netatalk":"2.0.3-249.23.3.1","netatalk-devel":"2.0.3-249.23.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 11 SP4","name":"netatalk","purl":"pkg:rpm/suse/netatalk&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.0.3-249.23.3.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for netatalk fixes the following issues:\n\nSecurity issue fixed:\n\n- CVE-2018-1160 Fixed a missing bounds check in the handling of the DSI\n  OPEN SESSION request, which allowed an unauthenticated to overwrite memory\n  with data of their choice leading for arbitrary code execution with root\n  privileges. (bsc#1119540)\n","id":"SUSE-SU-2018:4214-1","modified":"2018-12-21T05:45:58Z","published":"2018-12-21T05:45:58Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20184214-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1119540"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-1160"}],"related":["CVE-2018-1160"],"summary":"Security update for netatalk","upstream":["CVE-2018-1160"]}