[重要安全性通知] 发现假冒 Qfinder Pro 网站。了解详情 >

安全ID : NAS-201805-10

Security Advisory for PHP Vulnerabilities in QTS


  • 发布日期 : May 10, 2018

  • 通用漏洞披露 : CVE-2016-1283 | CVE-2017-16642 | CVE-2018-5711 | CVE-2018-5712

  • 受影响产品: QTS 4.3.3: build 20180126 and earlier versions
    QTS 4.3.4: build 20180215 and earlier versions

严重程度

Moderate

状态

已解决


Summary

Several vulnerabilities have been discovered on PHP 5.6.32 and earlier versions. These affect QTS 4.3.3 build 20180126, 4.3.4 build 20180215, and their earlier versions.

If successfully exploited, these vulnerabilities could allow attackers to access sensitive information on the NAS, launch denial-of-service (DoS), or Cross-Site-Scripting (XSS) attacks.

We have already fixed these issues in the following QTS versions

  • QTS 4.3.3: build 20180402 and later
  • QTS 4.3.4: build 20180315 and later

Recommendation

To fix these vulnerabilities, you must update QTS to the following versions.

  • QTS 4.3.3: build 20180402 or later
  • QTS 4.3.4: build 20180315 or later

Installing the QTS Update

  1. Log on to QTS as administrator.
  2. Go to Control Panel > System > Firmware Update.
  3. Under Live Update, click Check for Update.
    QTS downloads and installs the latest available update.

 

修订历史: V1.0 (May 10, 2018) - Published

选择规格

      显示更多 隐藏更多
      欢迎随时咨询! 欢迎随时咨询!
      back to top