Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Jeremy Kemp

#39694de 53,639
6.8CVSS total
Vulnerabilidades · 1
PT-2015-5936
6.8
2015-05-30
Synology · Cloud Station · CVE-2015-2851
**Name of the Vulnerable Software and Affected Versions** Synology Cloud Station versions 1.1-2291 through 3.1-3320 **Description** The issue allows local users to change the ownership of arbitrary files and consequently obtain root access by specifying a filename. This is related to the `client chown` functionality in the sync client. **Recommendations** For versions 1.1-2291 through 3.1-3320, consider restricting access to the `client chown` function to prevent unauthorized changes to file ownership until a fix is available.