OwnCloud Server Arbitrary Code Execution Vulnerability (CVE-2015-7699)
OwnCloud Server Arbitrary Code Execution Vulnerability (CVE-2015-7699)
Release date:
Updated on:
Affected Systems:
ownCloud ownCloud Server 〈 8.0.7
ownCloud ownCloud Server 〈 7.0.9
ownCloud ownCloud Server 8.1.x-8.1.2
Description:
CVE (CAN) ID: CVE-2015-7699
OwnCloud is a solution for source file synchronization and sharing.
Versions earlier than ownCloud Server 7.0.9, versions earlier than 8.0.7, 8.1.x-8.1.2, and files_external app have a security vulnerability. remote users can execute arbitrary code by constructing the mount point option.
<* Source: Johannes kliann
*>
Suggestion:
Vendor patch:
OwnCloud
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://owncloud.org/security/advisory? Oc-sa-2015-018
Build a private cloud with Nginx + ownCloud + PHP + MySQL in CentOS7
Install OwnCloud 7.0.4 on Ubuntu
Building personal private cloud storage ownCloud in CentOS 6.3
Install ownCloud 4.0.6 platform on Ubuntu 12.04 LTS
OwnCloud 6.2 installation in CentOS 4.0
Use ownCloud in Ubuntu 12.04 to build a private storage cloud
How to install OwnCloud 6 in Ubuntu/Debian/CentOS/Fedora/OpenSUSE and derivative systems
This article permanently updates the link address: