Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophoto_dsm_user --copy-no-ea" command.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://www.synology.com/en-us/releaseNote/PhotoStation | release notes vendor advisory |
http://seclists.org/oss-sec/2016/q1/236 | mailing list exploit third party advisory |