CVE-2024-39349

A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjansson component and it does not affect the upstream library. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:synology:bc500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:bc500:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:synology:tc500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:tc500:-:*:*:*:*:*:*:*

History

04 Mar 2025, 18:43

Type Values Removed Values Added
References () https://www.synology.com/en-global/security/advisory/Synology_SA_23_15 - () https://www.synology.com/en-global/security/advisory/Synology_SA_23_15 - Vendor Advisory
CPE cpe:2.3:o:synology:tc500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:tc500:-:*:*:*:*:*:*:*
cpe:2.3:h:synology:bc500:-:*:*:*:*:*:*:*
cpe:2.3:o:synology:bc500_firmware:*:*:*:*:*:*:*:*
First Time Synology tc500 Firmware
Synology bc500
Synology bc500 Firmware
Synology tc500
Synology

21 Nov 2024, 09:27

Type Values Removed Values Added
Summary
  • (es) Se encuentra una vulnerabilidad con respecto a la copia del búfer sin verificar el tamaño de la entrada ("Classic Buffer Overflow") en el componente libjansson y no afecta a la librería ascendente. Esto permite a atacantes remotos ejecutar código arbitrario a través de vectores no especificados. Los siguientes modelos con versiones de firmware de cámara Synology anteriores a 1.0.7-0298 pueden verse afectados: BC500 y TC500.
References () https://www.synology.com/en-global/security/advisory/Synology_SA_23_15 - () https://www.synology.com/en-global/security/advisory/Synology_SA_23_15 -

28 Jun 2024, 10:27

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-28 06:15

Updated : 2025-03-04 18:43


NVD link : CVE-2024-39349

Mitre link : CVE-2024-39349

CVE.ORG link : CVE-2024-39349


JSON object : View

Products Affected

synology

  • tc500_firmware
  • bc500_firmware
  • tc500
  • bc500
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')