Synology Fixes File-Takeover Flaw in Cloud Station OS X Client
Summary
There is a vulnerability in some versions of Synology’s Cloud Station client for OS X that can enable any user to take over system files and gain complete control of the machine. “The Synology Cloud Station sync client for OS X contains an executable named that allows users to change the ownership of files. This allows any user the ability to change ownership of arbitrary system files, which may be leveraged to gain root privileges and fully compromise the host,” an advisory from CERT at Carnegie Mellon University says. The tool was originally designed to ease the upgrade process of the Cloud Station client, and was included starting from build 2291. Synology also has fixed a separate command-injection vulnerability in its Photo Station application that could lead to an attacker being able to compromise a NAS device.