client_chown in the sync client in Synology Cloud Station 1.1-2291 through 3.1-3320 on OS X allows local users to change the ownership of arbitrary files, and consequently obtain root access, by specifying a filename.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/74826 | vdb entry |
http://www.kb.cert.org/vuls/id/BLUU-9VBU45 | third party advisory us government resource |
http://www.kb.cert.org/vuls/id/551972 | third party advisory us government resource |