Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 412897 - <www-apps/owncloud-3.0.2 : Password Reset Vulnerability
Summary: <www-apps/owncloud-3.0.2 : Password Reset Vulnerability
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/48856/
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-04-21 09:50 UTC by Agostino Sarubbo
Modified: 2012-04-23 10:46 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-04-21 09:50:40 UTC
From secunia:

Description
luks has discovered a vulnerability in ownCloud, which can be exploited by malicious people to bypass certain security restrictions.

The vulnerability is caused due to the core/lostpassword/index.php script generating predictable tokens for password resets and can be exploited to change the passwords of arbitrary users.

The vulnerability is confirmed in version 3.0.1. Prior versions may also be affected.


Solution
Update to version 3.0.2.
Comment 1 Bernard Cafarelli gentoo-dev 2012-04-23 08:53:57 UTC
Last vulnerable version (3.0.0) removed from tree, only 3.0.2 is left now
Comment 2 Agostino Sarubbo gentoo-dev 2012-04-23 10:46:34 UTC
thanks, fixed