Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 437942 (CVE-2012-5056) - <www-apps/owncloud-4.0.8 version bump (CVE-2008-4107,CVE-2012-{5056,5057,5336})
Summary: <www-apps/owncloud-4.0.8 version bump (CVE-2008-4107,CVE-2012-{5056,5057,5336})
Status: RESOLVED FIXED
Alias: CVE-2012-5056
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://owncloud.org/changelog/
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-10-11 08:54 UTC by Bernard Cafarelli
Modified: 2012-10-11 13:33 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Bernard Cafarelli gentoo-dev 2012-10-11 08:54:27 UTC
From upstream, these versions fix multiple security issues (changelog is not online yet). Just a heads up for now, but CVEs will probably come soon

On our side, 4.0.8 and 4.5.0 are now in tree, previous version removed
Comment 1 Sean Amoss (RETIRED) gentoo-dev Security 2012-10-11 13:33:15 UTC
Thanks, Bernard.

Upstream changelog at $URL:

Version 4.0.8 Oct 10th 2012
Show Login Button when user and password are autocompleted
Sanitize LDAP base, user and groups
Security: Fix for insufficiently Random Values (CVE-2008-4107)
Security: Fixed multiple XSS vulnerabilities (CVE-2012-5056)
Security: Fixed a HTTP header injection (CVE-2012-5057)
Security: Fixed an Auth bypass in /lib/base.php (CVE-2012-5336)
Download: http://download.owncloud.org/releases/owncloud-4.0.8.tar.bz2
MD5: http://download.owncloud.org/releases/owncloud-4.0.8.tar.bz2.md5

Closing noglsa for ~arch only.