Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 437942 (CVE-2012-5056)

Summary: <www-apps/owncloud-4.0.8 version bump (CVE-2008-4107,CVE-2012-{5056,5057,5336})
Product: Gentoo Security Reporter: Bernard Cafarelli <voyageur>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: voyageur, web-apps
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://owncloud.org/changelog/
Whiteboard: ~4 [noglsa]
Package list:
Runtime testing required: ---

Description Bernard Cafarelli gentoo-dev 2012-10-11 08:54:27 UTC
From upstream, these versions fix multiple security issues (changelog is not online yet). Just a heads up for now, but CVEs will probably come soon

On our side, 4.0.8 and 4.5.0 are now in tree, previous version removed
Comment 1 Sean Amoss (RETIRED) gentoo-dev Security 2012-10-11 13:33:15 UTC
Thanks, Bernard.

Upstream changelog at $URL:

Version 4.0.8 Oct 10th 2012
Show Login Button when user and password are autocompleted
Sanitize LDAP base, user and groups
Security: Fix for insufficiently Random Values (CVE-2008-4107)
Security: Fixed multiple XSS vulnerabilities (CVE-2012-5056)
Security: Fixed a HTTP header injection (CVE-2012-5057)
Security: Fixed an Auth bypass in /lib/base.php (CVE-2012-5336)
Download: http://download.owncloud.org/releases/owncloud-4.0.8.tar.bz2
MD5: http://download.owncloud.org/releases/owncloud-4.0.8.tar.bz2.md5

Closing noglsa for ~arch only.