First published: Tue Jun 13 2017(Updated: )
A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc/*/cmdline".
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Photo Station | =6.0-2528 | |
Synology Photo Station | =6.0-2636 | |
Synology Photo Station | =6.0-2638 | |
Synology Photo Station | =6.0-2639 | |
Synology Photo Station | =6.0-2640 | |
Synology Photo Station | =6.3-2944 | |
Synology Photo Station | =6.3-2958 | |
Synology Photo Station | =6.3-2960 | |
Synology Photo Station | =6.3-2962 | |
Synology Photo Station | =6.3-2963 | |
Synology Photo Station | =6.3-2964 | |
Synology Photo Station | =6.3-2965 | |
Synology Photo Station | =6.4-3166 | |
Synology Photo Station | =6.5.0-3218 | |
Synology Photo Station | =6.5.1-3223 | |
Synology Photo Station | =6.5.2-3225 | |
Synology Photo Station | =6.5.3-3226 | |
Synology Photo Station | =6.6.0-3339 | |
Synology Photo Station | =6.6.1-3345 | |
Synology Photo Station | =6.6.1-3346 | |
Synology Photo Station | =6.6.2-3346 | |
Synology Photo Station | =6.6.3-3347 | |
Synology Photo Station | =6.7.0-3414 | |
Synology Photo Station | =6.7.1-3419 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.