|
|
Log in / Subscribe / Register

owncloud: multiple vulnerabilities

Package(s):owncloud CVE #(s):
Created:January 25, 2016 Updated:January 27, 2016
Description: From the ownCloud security advisories:

OC-SA-2016-001: A Cross-site scripting (XSS) vulnerability in the OCS discovery provider in ownCloud Servers allows remote attackers to inject arbitrary web script or HTML via the URL resulting in a reflected Cross-Site-Scripting.

OC-SA-2016-002: Due to an incorrect usage of an ownCloud internal file system function the passed path to the file scanner was resolved relatively. An authenticated adversary may thus be able to get a listing of files existing on the filesystem. However, it is not possible to access any of these files.

This causes a massive server load and thus an enumeration of the whole server content is unlikely due to the high risk of Denial of Service.

OC-SA-2016-003: Due to a incorrect usage of the getOwner function of the ownCloud virtual filesystem,done authenticated users with incoming shares of other users are able to access files beginning with ".v" of the sharing user. This can only be exploited if the "files_versions" application is enabled on the server.

OC-SA-2016-004: ownCloud returns exception error messages to the user in two different places, allowing an authenticated adversary to gain information about the installation path of the ownCloud instance. There is no further information disclosure.

Alerts:
Fedora FEDORA-2016-9422448006 owncloud 2016-01-24
Fedora FEDORA-2016-a576196426 owncloud 2016-01-24

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds