CVE-2022-49040: Buffer Overflow
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in connection management functionality in Synology Drive Client before 3.4.0-15721 allows local users with administrator privileges to crash the client via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-49040?
CVE-2022-49040 is classified as a 'Classic Buffer Overflow' vulnerability with significant potential impact due to its ability to crash the Synology Drive Client.
How do I fix CVE-2022-49040?
To fix CVE-2022-49040, update the Synology Drive Client to version 3.4.0-15721 or later.
Who is affected by CVE-2022-49040?
CVE-2022-49040 affects local users with administrator privileges on systems running Synology Drive Client versions prior to 3.4.0-15721.
What is the nature of the vulnerability in CVE-2022-49040?
CVE-2022-49040 allows for a buffer overflow due to a buffer copy without size checks in the connection management functionality.
Can CVE-2022-49040 be exploited remotely?
CVE-2022-49040 requires local administrator access for exploitation, so it cannot be exploited remotely.