Security ID : NAS-201701-06
Security Vulnerabilities Addressed in QTS 4.2.3 Builds 20170121 and 20170124
Release date : January 6, 2017
Affected products: All QNAP NAS running QTS 4.2.2 and earlier
Severity
Moderate
Status
Resolved
Summary
QTS 4.2.3 Builds 20170121 and 20170124 include security fixes for the heap overflow vulnerability reported by bashis and the firmware update vulnerabilities reported by F-Secure.
Note: Install the appropriate build for your NAS model.
Build 20170124: TS-809 and TS-809U only
Build 20170121: All other models
Solution
Installing the Update
- Download the package from the QNAP Download page: https://www.qnap.com/download/.
- Log on as administrator to the QTS web console.
- Go to "Control Panel" > "System" > "Firmware Update" > "Firmware Update".
- Click "Browse" and then locate the package on your computer.
- Click "Update System".
Note: After manually installing the update, you can choose to enable live updates from the Live Update tab.
If you have any questions regarding this issue, please contact us at http://helpdesk.qnap.com/
Revision History: 2017-01-26