Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 476522 - <www-apps/owncloud-{4.5.13,5.0.8}: multiple security issues (oC-SA-2013-029,oC-SA-2013-030)
Summary: <www-apps/owncloud-{4.5.13,5.0.8}: multiple security issues (oC-SA-2013-029,o...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://owncloud.org/releases/Changelog
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-07-11 11:11 UTC by Frank Krömmelbein
Modified: 2013-10-06 15:22 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Frank Krömmelbein 2013-07-11 11:11:28 UTC
A version bump is again required, this seems to never stop with this software...

http://owncloud.org/releases/Changelog

-------------------------------
Release  "5.0.8"
July 9. 2013

- SECURITY: XSS vulnerability in "Share Interface" (oC-SA-2013-029)
- SECURITY: Authentication bypass in "user_webdavauth" (oC-SA-2013-030)
- New anonymous upload feature
- Fix syncing of external filesystems
- External filesystems performance improvements
- Improve compatibility with Oracle
- Improved and simplified theming
- Internet explorer 8 fixes
- Fixes for partial file uploads
- LDAP: fix handling of User and Group Bases
- Improved and more robust upgrade system
- A lot of encryption system fixes
- Do not add groups if user has no groups
- Several Contacts fixes
- A lot of smaller bugfixes all over the place

Download: http://download.owncloud.org/community/owncloud-5.0.8.tar.bz2
MD5: http://download.owncloud.org/community/owncloud-5.0.8.tar.bz2.md5

-------------------------------
Release  "4.5.13"
July 9. 2013

- SECURITY: Authentication bypass in "user_webdavauth" (oC-SA-2013-030)
- Fixed deleting old files versions

Download: http://download.owncloud.org/community/owncloud-4.5.13.tar.bz2
MD5: http://download.owncloud.org/community/owncloud-4.5.13.tar.bz2.md5
Comment 1 cyberbat 2013-07-16 21:21:46 UTC
5.0.9 is out:
Release  "5.0.9"
July 15. 2013

- Fixes for mounting an WebDAV into an ownCloud
- Improved expiration of older versions in the case of a full storage
- IE8 fixes
- Increased speed when syncing shared files
- Oracle compatibility fixes
- Make upgrade routine more robust
- Fix gallery for certain php configurations
- Fix pdf viewer close button
- user_external fixes 
- Several smaller fixes
Comment 2 ron widler 2013-07-17 21:57:59 UTC
just tested upgrading to 5.0.9 by copying the ebuild from 5.0.7, and via webapp-config -U, everything went fine for me. (with postgresql 9.0 as a db backend)
Comment 3 Tomáš Chvátal (RETIRED) gentoo-dev 2013-07-27 12:39:40 UTC
Updated the ebuilds in cvs, so you can proceed further.
Comment 4 grischa 2013-08-13 16:20:51 UTC
several security fixes in this one....

Version 5.0.10 Aug 12th 2013

    Configurable logfile date format
    Several Oracle fixes
    Several MSSQL fixes
    Make default language configurable
    New CLI upgrade script
    Correctly calculate folder size
    Fix display of search results
    Database upgrade fixes
    Smaller filesystem cache fixes
    Remember password fixes
    Encryption fixes
    Fix problems with german “Umlauts” in folder name
    IE fixes
    Improved upgrade logging
    Improved external storage status display
    Flicker free versions dropdown
    Don’t create empty versions
    Less noisy debug logfile
    Don’t show firstrunwizard during upgrade
    Several Calendar fixes
    Contacts fixes
    Fixes for Gallery
    Several smaller fixes
Comment 5 cyberbat 2013-08-13 16:49:00 UTC
(In reply to grischa from comment #4)
> several security fixes in this one....
> 
> Version 5.0.10 Aug 12th 2013
> 
>     Configurable logfile date format
>     Several Oracle fixes
>     Several MSSQL fixes
>     Make default language configurable
>     New CLI upgrade script
>     Correctly calculate folder size
>     Fix display of search results
>     Database upgrade fixes
>     Smaller filesystem cache fixes
>     Remember password fixes
>     Encryption fixes
>     Fix problems with german “Umlauts” in folder name
>     IE fixes
>     Improved upgrade logging
>     Improved external storage status display
>     Flicker free versions dropdown
>     Don’t create empty versions
>     Less noisy debug logfile
>     Don’t show firstrunwizard during upgrade
>     Several Calendar fixes
>     Contacts fixes
>     Fixes for Gallery
>     Several smaller fixes

There are no security fixes in 5.0.10, but it'll be good to see it in portage.
Comment 6 Chris Reffett (RETIRED) gentoo-dev Security 2013-08-27 01:07:21 UTC
GLSA vote: no.
Comment 7 Sergey Popov gentoo-dev 2013-08-28 07:06:17 UTC
Closing noglsa, as ~arch only