CVE-2021-26567: Buffer Overflow
Published Feb 26, 2021
·Updated
Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute arbitrary code via filename and pathname options.
Affected Software
15 affected components
Synology Diskstation Manager<6.2.3-25426-3
Synology Vs960hd Firmware
Synology Vs960hd
Synology Skynas Firmware
Synology Skynas
Synology Diskstation Manager Unified Controller=3.0
Synology Uc3200
Faad2 Project Faad2<2.2.7.1
Synology Diskstation Manager<6.2.3-25426-3
All of the following
Synology Vs960hd Firmware
Synology Vs960hd
All of the following
Synology Skynas Firmware
Synology Skynas
All of the following
Synology Diskstation Manager Unified Controller=3.0
Synology Uc3200
Remediation
Event History
Feb 26, 2021
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2021-26567.
2
What is the severity of CVE-2021-26567?
The severity of CVE-2021-26567 is high with a CVSS score of 7.8.
3
How does CVE-2021-26567 impact the affected software?
CVE-2021-26567 allows local attackers to execute arbitrary code in the affected software.
4
Which software versions are affected by CVE-2021-26567?
Synology DiskStation Manager up to version 6.2.3-25426-3 and Faad2 up to version 2.2.7.1 are affected by CVE-2021-26567.
5
How can I fix CVE-2021-26567?
Upgrade to a patched version of the affected software.