Synology-SA-17:69 File Station

Publish Time: 2017-11-15 13:26:44 UTC+8

Last Updated: 2017-12-08 16:11:42 UTC+8

Severity
Important
Status
Resolved

Abstract

CVE-2017-15893 allows remote authenticated users to write arbitrary files via a vulnerable version of File Station.

Severity

Affected

  • Products
    • File Station before 1.1.1-0099

Description

Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.

Mitigation

None

Update Availability

To fix the security issue, please go to DSM > Package Center and update File Station to 1.1.1-0099 or above.