Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 502970 - www-apps/owncloud : security fixes in versions 5.0.15 and 6.0.2 (CVE-2014-{2047,2049,2057,2585})
Summary: www-apps/owncloud : security fixes in versions 5.0.15 and 6.0.2 (CVE-2014-{20...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-02-27 13:46 UTC by Agostino Sarubbo
Modified: 2014-04-10 21:33 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-02-27 13:46:20 UTC
From ${URL} :

ownCloud versions 5.0.15 and 6.0.2 will fix "several security" issues:

http://owncloud.org/releases/Changelog

As noted in Mageia #12889, release candidates for these versions are available:

http://mailman.owncloud.org/pipermail/devel/2014-February/000036.html


@maintainer(s): since the package has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 Bernard Cafarelli gentoo-dev 2014-03-04 08:54:58 UTC
5.0.15 and 6.0.2 have been released upstream, bumped in tree (and vulnerable versions removed)
Comment 2 Chris Reffett (RETIRED) gentoo-dev Security 2014-03-04 15:02:41 UTC
Thank you very much. Closing noglsa.
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2014-04-10 21:33:38 UTC
CVE-2014-2585 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-2585):
  ownCloud before 5.0.15 and 6.x before 6.0.2, when the file_external app is
  enabled, allows remote authenticated users to mount the local filesystem in
  the user's ownCloud via the mount configuration.

CVE-2014-2057 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-2057):
  Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 6.0.2
  allow remote attackers to inject arbitrary web script or HTML via
  unspecified vectors.

CVE-2014-2049 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-2049):
  The default Flash Cross Domain policies in ownCloud before 5.0.15 and 6.x
  before 6.0.2 allows remote attackers to access user files via unspecified
  vectors.

CVE-2014-2047 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-2047):
  Session fixation vulnerability in ownCloud before 6.0.2, when PHP is
  configured to accept session parameters through a GET request, allows remote
  attackers to hijack web sessions via unspecified vectors.