Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 515672 - <www-apps/owncloud-{5.0.17,6.0.4}: several security issues fixed in versions 5.0.17 and 6.0.4 (CVE-2014-4929)
Summary: <www-apps/owncloud-{5.0.17,6.0.4}: several security issues fixed in versions ...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://owncloud.org/releases/Changelog
Whiteboard: ~2 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-06-29 13:23 UTC by Bernard Cafarelli
Modified: 2014-08-25 21:06 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Bernard Cafarelli gentoo-dev 2014-06-29 13:23:56 UTC
Per http://owncloud.org/releases/Changelog, both branches have a fix for a security issue (will be disclosed in two weeks)

I added 5.0.17 and 6.0.4 in tree, and removed older versions
Comment 1 Kristian Fiskerstrand (RETIRED) gentoo-dev 2014-06-29 13:30:22 UTC
Thank you Bernard. 

It will be interesting to see what the undisclosed security fix is, so will set the appropriate vulnerability level once we know. Until then; as far as I can see this package has never been stabilized so would not require a glsa, meaning you've really solved it already :)
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2014-07-03 14:54:39 UTC
Maintainers, thank you for your work.

We are going to leave it in [cleanup] whiteboard so that we can add vulnerability and CVE when they are released.
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2014-08-25 21:03:23 UTC
CVE-2014-4929 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-4929):
  Directory traversal vulnerability in the routing component in ownCloud
  Server before 5.0.17 and 6.0.x before 6.0.4 allows remote attackers to
  include and execute arbitrary local files via a .. (dot dot) in a filename,
  related to index.php.