CVE-2017-11156
Summary
| CVE | CVE-2017-11156 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-14 19:29:00 UTC |
| Updated | 2019-10-09 23:21:00 UTC |
| Description | Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows remote authenticated users to execute arbitrary code by uploading an executable via unspecified vectors. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Synology | Download Station | 3.2-2295 | All | All | All |
| Application | Synology | Download Station | 3.3-2382 | All | All | All |
| Application | Synology | Download Station | 3.3-2383 | All | All | All |
| Application | Synology | Download Station | 3.3-2386 | All | All | All |
| Application | Synology | Download Station | 3.4-2477 | All | All | All |
| Application | Synology | Download Station | 3.4-2478 | All | All | All |
| Application | Synology | Download Station | 3.4-2480 | All | All | All |
| Application | Synology | Download Station | 3.4-2485 | All | All | All |
| Application | Synology | Download Station | 3.4-2486 | All | All | All |
| Application | Synology | Download Station | 3.4-2489 | All | All | All |
| Application | Synology | Download Station | 3.4-2490 | All | All | All |
| Application | Synology | Download Station | 3.4-2514 | All | All | All |
| Application | Synology | Download Station | 3.4-2555 | All | All | All |
| Application | Synology | Download Station | 3.4-2557 | All | All | All |
| Application | Synology | Download Station | 3.4-2558 | All | All | All |
| Application | Synology | Download Station | 3.5-2638 | All | All | All |
| Application | Synology | Download Station | 3.5-2705 | All | All | All |
| Application | Synology | Download Station | 3.5-2706 | All | All | All |
| Application | Synology | Download Station | 3.5-2955 | All | All | All |
| Application | Synology | Download Station | 3.5-2956 | All | All | All |
| Application | Synology | Download Station | 3.5-2962 | All | All | All |
| Application | Synology | Download Station | 3.5-2963 | All | All | All |
| Application | Synology | Download Station | 3.5-2967 | All | All | All |
| Application | Synology | Download Station | 3.5-2968 | All | All | All |
| Application | Synology | Download Station | 3.5-2970 | All | All | All |
| Application | Synology | Download Station | 3.5-2973 | All | All | All |
| Application | Synology | Download Station | 3.5-2980 | All | All | All |
| Application | Synology | Download Station | 3.5-2982 | All | All | All |
| Application | Synology | Download Station | 3.8.0-3416 | All | All | All |
| Application | Synology | Download Station | 3.8.1-3420 | All | All | All |
| Application | Synology | Download Station | 3.8.2-3455 | All | All | All |
| Application | Synology | Download Station | 3.8.3-3458 | All | All | All |
| Application | Synology | Download Station | 3.8.4-3468 | All | All | All |
| Application | Synology | Download Station | 3.2-2295 | All | All | All |
| Application | Synology | Download Station | 3.3-2382 | All | All | All |
| Application | Synology | Download Station | 3.3-2383 | All | All | All |
| Application | Synology | Download Station | 3.3-2386 | All | All | All |
| Application | Synology | Download Station | 3.4-2477 | All | All | All |
| Application | Synology | Download Station | 3.4-2478 | All | All | All |
| Application | Synology | Download Station | 3.4-2480 | All | All | All |
| Application | Synology | Download Station | 3.4-2485 | All | All | All |
| Application | Synology | Download Station | 3.4-2486 | All | All | All |
| Application | Synology | Download Station | 3.4-2489 | All | All | All |
| Application | Synology | Download Station | 3.4-2490 | All | All | All |
| Application | Synology | Download Station | 3.4-2514 | All | All | All |
| Application | Synology | Download Station | 3.4-2555 | All | All | All |
| Application | Synology | Download Station | 3.4-2557 | All | All | All |
| Application | Synology | Download Station | 3.4-2558 | All | All | All |
| Application | Synology | Download Station | 3.5-2638 | All | All | All |
| Application | Synology | Download Station | 3.5-2705 | All | All | All |
| Application | Synology | Download Station | 3.5-2706 | All | All | All |
| Application | Synology | Download Station | 3.5-2955 | All | All | All |
| Application | Synology | Download Station | 3.5-2956 | All | All | All |
| Application | Synology | Download Station | 3.5-2962 | All | All | All |
| Application | Synology | Download Station | 3.5-2963 | All | All | All |
| Application | Synology | Download Station | 3.5-2967 | All | All | All |
| Application | Synology | Download Station | 3.5-2968 | All | All | All |
| Application | Synology | Download Station | 3.5-2970 | All | All | All |
| Application | Synology | Download Station | 3.5-2973 | All | All | All |
| Application | Synology | Download Station | 3.5-2980 | All | All | All |
| Application | Synology | Download Station | 3.5-2982 | All | All | All |
| Application | Synology | Download Station | 3.8.0-3416 | All | All | All |
| Application | Synology | Download Station | 3.8.1-3420 | All | All | All |
| Application | Synology | Download Station | 3.8.2-3455 | All | All | All |
| Application | Synology | Download Station | 3.8.3-3458 | All | All | All |
| Application | Synology | Download Station | 3.8.4-3468 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Synology-SA-17:28 Download Station | Synology Inc. | CONFIRM | www.synology.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.