-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
_______________________________________________________________________
Mandriva Linux Security Advisory MDVSA-2015:191
http://www.mandriva.com/en/support/security/
_______________________________________________________________________
Package : owncloud
Date : April 1, 2015
Affected: Business Server 2.0
_______________________________________________________________________
Problem Description:
Multiple vulnerabilities has been discovered and corrected in owncloud:
* Multiple stored XSS in contacts application (oC-SA-2015-001)
* Multiple stored XSS in documents application (oC-SA-2015-002)
* Bypass of file blacklist (oC-SA-2015-004)
The updated packages have been upgraded to the 7.0.5 version where
these security flaws has been fixed.
_______________________________________________________________________
References:
https://owncloud.org/changelog/
https://owncloud.org/security/advisory/?id=oc-sa-2015