[ MDVSA-2015:191 ] owncloud

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 _______________________________________________________________________

 Mandriva Linux Security Advisory                         MDVSA-2015:191
 http://www.mandriva.com/en/support/security/
 _______________________________________________________________________

 Package : owncloud
 Date    : April 1, 2015
 Affected: Business Server 2.0
 _______________________________________________________________________

 Problem Description:

 Multiple vulnerabilities has been discovered and corrected in owncloud:
 
 * Multiple stored XSS in contacts application (oC-SA-2015-001)
 
 * Multiple stored XSS in documents application (oC-SA-2015-002)
 
 * Bypass of file blacklist (oC-SA-2015-004)
 
 The updated packages have been upgraded to the 7.0.5 version where
 these security flaws has been fixed.
 _______________________________________________________________________

 References:

 https://owncloud.org/changelog/
 https://owncloud.org/security/advisory/?id=oc-sa-2015

Leave a Reply