Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 448270 (CVE-2012-5665) - <www-apps/owncloud-{4.0.10,4.5.5}: Security bump - authentication bypass and XSS (CVE-2012-{5665,5666})
Summary: <www-apps/owncloud-{4.0.10,4.5.5}: Security bump - authentication bypass and ...
Status: RESOLVED FIXED
Alias: CVE-2012-5665
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-12-23 10:46 UTC by Bug
Modified: 2012-12-29 13:15 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Bug 2012-12-23 10:46:37 UTC
A new version is available.

Please also check the required USE-Flags
because php-5.4.9 no longer have have "sqlite3"

  (dev-lang/php-5.4.9::gentoo, ebuild scheduled for merge) conflicts with
    dev-lang/php[curl,gd,json,mysql,pdo,sqlite3,xmlwriter,zip] required by (www-apps/owncloud-4.5.4::gentoo, installed)

Reproducible: Always
Comment 1 Jay Carter 2012-12-23 23:57:27 UTC
This should be considered more than a simple version bump as 4.5.5 has security fixes including an auth bypass and XSS issue.

Changelog:

Version 4.5.5 Dec 20th 2012

    Show drag and drop shadow for Firefox
    Fix Knowledgebase under certain conditions
    Fix setting of sharing password
    Fix setting of sharing password
    Several sharing fixes
    Fixversioning during sharing
    Fix mounting of external filesystems especially CIFS
    Fix several PHP warnings
    Show /Shared as standard directory
    Fix session management for running several ownClouds on the same host
    Fix WebDAV quota enforement
    Fix CalDAV with LDAP users
    Better warning about missing dependencies
    Add warning about conflicting WebDAV auth and LDAP backend
    Restore send sharing link my email
    Fix encoding problem with mounting of CIFS filesystems
    Fix mimetype icons for new files
    Fix the folder size calculation
    Fix for deleting multiple files
    Fix for controling the data dir with LDAP
    Security: Auth bypass in user_webdavauth and user_ldap (oC-SA-2012-006)
    Security: XSS vulnerability in bookmarks (oC-SA-2012-007)
Comment 2 Bernard Cafarelli gentoo-dev 2012-12-27 12:15:44 UTC
Indeed, thanks for the report! Reassigning to security per:
- Auth bypass in user_webdavauth and user_ldap (oC-SA-2012-001 / e
CVE-2012-5665)
- XSS vulnerability in bookmarks (oC-SA-2012-007 / CVE-2012-5666)
(also thanks Lukas Reschke upstream for the notification)

I just added 4.0.10 and 4.5.5 to tree, removed the older versions (and changed USE flag to sqlite to follow php, supporting php-5.4.9)
Comment 3 Sean Amoss (RETIRED) gentoo-dev Security 2012-12-29 13:15:43 UTC
Thanks, everyone.