QNAP przedstawił łatkę w postaci Qfixes dla open-sourcowej usługi serwera Samba w serwerach NAS.​


afeeds_feedburner_com__r_cdrinfo__4_tfBJx_z5d1Q_.gif


Kontynuuj czytanie...
 
Security Advisory for Samba Writable Share Vulnerability
QNAP Systems, Inc. - Network Attached Storage (NAS)

Fixes]
  • System logs do not display unexpected errors when users back up files from the NAS to external devices twice using Backup Station.
  • Non-admin users in the administrator group can successfully log on to NAS again via FAQ SSH.
  • Resource Monitor can correctly display CPU and memory usage when users enable version control for Qsync and then synchronize a large number of files.
  • Users can directly open the folder of downloaded files when clicking a completed download task in Download Station.
  • Users can no longer access the "Homes" folder via FTP when the folder permissions are denied.
  • Users can still access the "Multimedia" folder and add media folders after uploading certain folders via File Station.
  • Fixed a remote code execution vulnerability in Samba. (CVE-2017-7494)
  • Fixed multiple security vulnerabilities regarding input validation and access control.
 
Ostatnio edytowane przez moderatora:
Oznaczyłeś post użytkownika jako rozwiązanie swojego pytania. Jeśli odpowiedź tego użytkownika nie jest trafna, zalecamy usunięcie rozwiązania z jego postu.