OwnCloud Desktop Client man-in-the-middle attack Vulnerability (CVE-2015-4456)
OwnCloud Desktop Client man-in-the-middle attack Vulnerability (CVE-2015-4456)
Release date:
Updated on:
Affected Systems:
OwnCloud Desktop Client <1.8.2
Description:
CVE (CAN) ID: CVE-2015-4456
OwnCloud is a solution for source file synchronization and sharing.
In versions earlier than ownCloud Desktop Client 1.8.2, no QNetworkReply: ignoreSslErrors with the ignore Error List is called. Man-in-the-middle attackers use a self-signed certificate to connect to the corresponding server and bypass the user certificate check, obtain sensitive information.
<* Source: Johannes kliann
*>
Suggestion:
Vendor patch:
OwnCloud
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://owncloud.org/security/advisory? Oc-sa-2015-009
Build a private cloud with Nginx + ownCloud + PHP + MySQL in CentOS7
Install OwnCloud 7.0.4 on Ubuntu
Building personal private cloud storage ownCloud in CentOS 6.3
Install ownCloud 4.0.6 platform on Ubuntu 12.04 LTS
OwnCloud 6.2 installation in CentOS 4.0
Use ownCloud in Ubuntu 12.04 to build a private storage cloud
How to install OwnCloud 6 in Ubuntu/Debian/CentOS/Fedora/OpenSUSE and derivative systems
This article permanently updates the link address: