Vulnerability Description
Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-3226 allows local users to write to arbitrary files via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Synology | Photo Station | <= 6.5.2-3225 |
Related Weaknesses (CWE)
References
- http://seclists.org/oss-sec/2016/q1/236ExploitThird Party AdvisoryVDB Entry
- https://bamboofox.github.io/2017/03/20/Synology-Bug-Bounty-2016/#Vul-03-Read-WriExploitThird Party Advisory
- https://bamboofox.github.io/2017/03/20/Synology-Bug-Bounty-2016/#Vul-04-PrivilegExploitThird Party Advisory
- https://www.synology.com/en-global/support/security/Photo_Station_6_5_3_3226Release Notes
- http://seclists.org/oss-sec/2016/q1/236ExploitThird Party AdvisoryVDB Entry
- https://bamboofox.github.io/2017/03/20/Synology-Bug-Bounty-2016/#Vul-03-Read-WriExploitThird Party Advisory
- https://bamboofox.github.io/2017/03/20/Synology-Bug-Bounty-2016/#Vul-04-PrivilegExploitThird Party Advisory
- https://www.synology.com/en-global/support/security/Photo_Station_6_5_3_3226Release Notes
FAQ
What is CVE-2016-10330?
CVE-2016-10330 is a vulnerability with a CVSS score of 7.1 (HIGH). Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-3226 allows local users to write to arbitrary files via unspecified vectors.
How severe is CVE-2016-10330?
CVE-2016-10330 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-10330?
Check the references section above for vendor advisories and patch information. Affected products include: Synology Photo Station.