Mageia alert MGASA-2015-0256 (owncloud-client)
From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2015-0256: Updated owncloud-client package fixes security vulnerability | |
Date: | Sun, 5 Jul 2015 19:22:34 +0200 | |
Message-ID: | <20150705172234.D2E3C41D1D@valstar.mageia.org> |
MGASA-2015-0256 - Updated owncloud-client package fixes security vulnerability Publication date: 05 Jul 2015 URL: http://advisories.mageia.org/MGASA-2015-0256.html Type: security Affected Mageia releases: 4, 5 CVE: CVE-2015-4456 Description: ownCloud Desktop Client before 1.8.2 was vulnerable against MITM attacks when used in combination with self-signed certificates (CVE-2015-4456). The owncloud-client package has been updated to version 1.8.3, which fixes this issue as well as several other bugs References: - https://bugs.mageia.org/show_bug.cgi?id=16106 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4456 - https://owncloud.org/security/advisory/?id=oc-sa-2015-009 - https://owncloud.org/changelog/desktop/ - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4456 SRPMS: - 4/core/owncloud-client-1.8.3-1.mga4 - 5/core/owncloud-client-1.8.3-1.mga5