Debian Security Advisory
DSA-3373-1 owncloud -- security update
- Date Reported:
- 18 Oct 2015
- Affected Packages:
- owncloud
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 800126.
In Mitre's CVE dictionary: CVE-2015-4716, CVE-2015-4717, CVE-2015-4718, CVE-2015-5953, CVE-2015-5954, CVE-2015-6500, CVE-2015-6670, CVE-2015-7699. - More information:
-
Multiple vulnerabilities were discovered in ownCloud, a cloud storage web service for files, music, contacts, calendars and many more. These flaws may lead to the execution of arbitrary code, authorization bypass, information disclosure, cross-site scripting or denial of service.
For the stable distribution (jessie), these problems have been fixed in version 7.0.4+dfsg-4~deb8u3.
For the testing distribution (stretch), these problems have been fixed in version 7.0.10~dfsg-2 or earlier versions.
For the unstable distribution (sid), these problems have been fixed in version 7.0.10~dfsg-2 or earlier versions.
We recommend that you upgrade your owncloud packages.