First published: Thu Sep 26 2024(Updated: )
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synology Drive Client before 3.5.0-16084 allows remote attackers to overwrite trivial buffers and crash the client via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Drive Client | <3.5.0-16084 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-52946 is classified as a critical buffer overflow vulnerability that can allow remote attackers to crash the Synology Drive Client.
To remediate CVE-2023-52946, upgrade the Synology Drive Client to version 3.5.0-16084 or later.
CVE-2023-52946 specifically affects the vss service component in Synology Drive Client before version 3.5.0-16084.
No, CVE-2023-52946 primarily allows for client crashes but does not directly facilitate data leakage.
CVE-2023-52946 can be exploited by remote attackers to overwrite trivial buffers via unspecified vectors.