vendor:
VioStor NVR, QNAP NAS, Celvin NAS
by:
Anonymous
7,5
CVSS
HIGH
Heap and Stack Overflow
119, 120
CWE
Product Name: VioStor NVR, QNAP NAS, Celvin NAS
Affected Version From: QTS 4.2.2 (Build 20161214)
Affected Version To: QVR 5.1.x, QTS 4.3.2 Beta, QTS older than 4.2.3 (build 20170121), Celvin NAS older than 4.2.3 (build 20170110)
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2017
Classic Heap and Stack Overflows in QNAP VioStor NVR, QNAP NAS, Fujitsu Celvin NAS
QNAP VioStor NVR, QNAP NAS, and Fujitsu Celvin NAS are vulnerable to classic heap and stack overflows. The tags 'u' (user) and 'p' (password) suffer from heap overflow, which allows an attacker to overwrite the heap wilderness top chunk size. The tag 'pp' (sysApp) suffers from stack overflow, which allows an attacker to overwrite libc_argv[0].
Mitigation:
Upgrade to the latest version of QTS, QVR, and Celvin NAS.