CVE-2017-12074: Path Traversal
Published Aug 24, 2017
·Updated
Directory traversal vulnerability in the SYNO.DNSServer.Zone.MasterZoneConf in Synology DNS Server before 2.2.1-3042 allows remote authenticated attackers to write arbitrary files via the domainname parameter.
Affected Software
1 affected component
Synology DNS Server<=2.2.0-3032
Event History
Aug 24, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-12074?
CVE-2017-12074 has a high severity rating as it allows remote authenticated attackers to write arbitrary files on the system.
2
How do I fix CVE-2017-12074?
To fix CVE-2017-12074, upgrade Synology DNS Server to version 2.2.1-3043 or later.
3
What systems are affected by CVE-2017-12074?
CVE-2017-12074 affects Synology DNS Server versions prior to 2.2.1-3042.
4
What type of vulnerability is CVE-2017-12074?
CVE-2017-12074 is a directory traversal vulnerability that can be exploited by authenticated attackers.
5
Can CVE-2017-12074 be exploited remotely?
Yes, CVE-2017-12074 can be exploited remotely by authenticated attackers.