First published: Mon Dec 04 2017(Updated: )
Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Photo Station | >=6.8<6.8.1-3458 | |
Synology Photo Station | >=6.3<6.3-2970 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12079 is a vulnerability that allows remote attackers to obtain arbitrary files in Synology Photo Station before 6.8.1-3458 and before 6.3-2970.
The severity of CVE-2017-12079 is high with a CVSS score of 7.5.
The CVE-2017-12079 vulnerability can be exploited by remote attackers to obtain arbitrary files via the prog_id field in picasa.php.
The Synology Photo Station versions before 6.8.1-3458 and before 6.3-2970 are affected by CVE-2017-12079.
To fix the CVE-2017-12079 vulnerability, it is recommended to update Synology Photo Station to version 6.8.1-3458 or 6.3-2970.