Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 413817 - www-apps/owncloud: XSS and CSRF vulnerabilities (CVE-2012-{2397,2398})
Summary: www-apps/owncloud: XSS and CSRF vulnerabilities (CVE-2012-{2397,2398})
Status: RESOLVED DUPLICATE of bug 412899
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial
Assignee: Gentoo Security
URL:
Whiteboard: ~4 [upstream]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-04-28 02:25 UTC by GLSAMaker/CVETool Bot
Modified: 2012-04-28 11:07 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2012-04-28 02:25:50 UTC
CVE-2012-2398 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2398):
  Cross-site scripting (XSS) vulnerability in files/ajax/download.php in
  ownCloud 3.0.2 allows remote attackers to inject arbitrary web script or
  HTML via the files parameter, a different vulnerability than
  CVE-2012-2269.4.  NOTE: the provenance of this information is unknown; the
  details are obtained solely from third party information.

CVE-2012-2397 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2397):
  Cross-site request forgery (CSRF) vulnerability in ownCloud 3.0.2 allows
  remote attackers to hijack the authentication of arbitrary users for
  requests that insert cross-site scripting (XSS) sequences via vectors
  involving contacts.  NOTE: the provenance of this information is unknown;
  the details are obtained solely from third party information.
Comment 1 Agostino Sarubbo gentoo-dev 2012-04-28 07:06:30 UTC
IS it a duplicate of 412899 ?
Comment 2 Sean Amoss (RETIRED) gentoo-dev Security 2012-04-28 11:07:51 UTC
(In reply to comment #1)
> IS it a duplicate of 412899 ?

It absolutely is.

*** This bug has been marked as a duplicate of bug 412899 ***