Release date:
Updated on:
Affected Systems:
OwnCloud <6.0.1
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-3963
OwnCloud is a solution for source file synchronization and sharing.
The ownCloud Server versions earlier than 6.0.1 do not have the correct check permission, which allows authenticated remote users to access any preview images of other users.
Building personal private cloud storage ownCloud in CentOS 6.3
Install ownCloud 4.0.6 platform on Ubuntu 12.04 LTS
OwnCloud 6.2 installation in CentOS 4.0
Use ownCloud in Ubuntu 12.04 to build a private storage cloud
How to install OwnCloud 6 in Ubuntu/Debian/CentOS/Fedora/OpenSUSE and derivative systems
<* Source: Lukas Reschke
Link: http://owncloud.org/about/security/advisories/oC-SA-2014-009/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
OwnCloud
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://download.owncloud.org/community/owncloud-6.0.1.tar.bz2
This article permanently updates the link address: