CVE Vulnerabilities

CVE-2015-2851

Published: May 30, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:L/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

client_chown in the sync client in Synology Cloud Station 1.1-2291 through 3.1-3320 on OS X allows local users to change the ownership of arbitrary files, and consequently obtain root access, by specifying a filename.

Affected Software

NameVendorStart VersionEnd Version
Cloud_stationSynology1.1-2291 (including)1.1-2291 (including)
Cloud_stationSynology2.0-2291 (including)2.0-2291 (including)
Cloud_stationSynology2.0-2402 (including)2.0-2402 (including)
Cloud_stationSynology2.1-2561 (including)2.1-2561 (including)
Cloud_stationSynology2.1-2570 (including)2.1-2570 (including)
Cloud_stationSynology2.1-2577 (including)2.1-2577 (including)
Cloud_stationSynology3.0-3005 (including)3.0-3005 (including)
Cloud_stationSynology3.0-3103 (including)3.0-3103 (including)
Cloud_stationSynology3.0-3108 (including)3.0-3108 (including)
Cloud_stationSynology3.0-3109 (including)3.0-3109 (including)
Cloud_stationSynology3.0-3111 (including)3.0-3111 (including)
Cloud_stationSynology3.1-3317 (including)3.1-3317 (including)
Cloud_stationSynology3.1-3320 (including)3.1-3320 (including)

References