CVE-2016-10323: High severity Synology Photo Station vulnerability
Published Apr 10, 2017
·Updated
Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophotodsmuser --copy-no-ea" command.
Affected Software
1 affected component
Synology Photo Station<6.3-2958
Event History
Apr 10, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10323?
CVE-2016-10323 is considered a high-severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2016-10323?
To fix CVE-2016-10323, users should upgrade Synology Photo Station to version 6.3-2958 or later.
3
Who is affected by CVE-2016-10323?
CVE-2016-10323 affects all versions of Synology Photo Station prior to 6.3-2958.
4
What is the nature of the vulnerability in CVE-2016-10323?
CVE-2016-10323 allows local users to gain elevated privileges through vulnerable setuid execution of a command.
5
What should I do if I cannot upgrade to fix CVE-2016-10323?
If upgrading is not possible for CVE-2016-10323, consider minimizing local user access and reviewing permissions to mitigate the risk.