A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors.
We have already fixed the vulnerability in the following versions:
Multimedia Console 2.1.1 ( 2023/03/29 ) and later
Multimedia Console 1.4.7 ( 2023/03/20 ) and later
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-23-29 |     | 
History
                    Tue, 24 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: qnap
Published: 2023-09-22T03:51:02.028Z
Updated: 2024-09-24T18:09:22.705Z
Reserved: 2023-01-11T20:15:53.085Z
Link: CVE-2023-23364
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-02T10:28:40.820Z
 NVD
                        NVD
                    Status : Modified
Published: 2023-09-22T04:15:54.213
Modified: 2024-11-21T07:46:02.070
Link: CVE-2023-23364
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow