~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2016-9468

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2016-9468
2
 
PublicDate: 2017-03-27
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9468
5
 
 https://github.com/nextcloud/server/commit/7350e13113c8ed484727a5c25331ec11d4d59f5f
6
 
 https://github.com/nextcloud/server/commit/a4cfb3ddc1f4cdb585e05c0e9b2f8e52a0e2ee3e
7
 
 https://github.com/owncloud/core/commit/96b8afe48570bc70088ccd8f897e9d71997d336e
8
 
 https://github.com/owncloud/core/commit/bcc6c39ad8c22a00323a114e9c1a0a834983fb35
9
 
 https://hackerone.com/reports/149798
10
 
 https://nextcloud.com/security/advisory/?id=nc-sa-2016-011
11
 
 https://owncloud.org/security/advisory/?id=oc-sa-2016-021
12
 
Description:
13
 
 Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6
14
 
 and 9.1.2 suffer from content spoofing in the dav app. The exception
15
 
 message displayed on the DAV endpoints contained partially
16
 
 user-controllable input leading to a potential misrepresentation of
17
 
 information.
18
 
Ubuntu-Description:
19
 
Notes:
20
 
Bugs:
21
 
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=835086
22
 
Priority: medium
23
 
Discovered-by:
24
 
Assigned-to:
25
 
 
26
 
Patches_nextcloud:
27
 
upstream_nextcloud: needs-triage
28
 
precise_nextcloud: DNE
29
 
precise/esm_nextcloud: DNE
30
 
trusty_nextcloud: DNE
31
 
vivid/stable-phone-overlay_nextcloud: DNE
32
 
vivid/ubuntu-core_nextcloud: DNE
33
 
xenial_nextcloud: DNE
34
 
yakkety_nextcloud: DNE
35
 
zesty_nextcloud: DNE
36
 
artful_nextcloud: DNE
37
 
bionic_nextcloud: DNE
38
 
devel_nextcloud: DNE
39
 
 
40
 
Patches_owncloud:
41
 
upstream_owncloud: needs-triage
42
 
precise_owncloud: ignored (reached end-of-life)
43
 
precise/esm_owncloud: DNE (precise was needs-triage)
44
 
trusty_owncloud: needs-triage
45
 
vivid/stable-phone-overlay_owncloud: DNE
46
 
vivid/ubuntu-core_owncloud: DNE
47
 
xenial_owncloud: DNE
48
 
yakkety_owncloud: DNE
49
 
zesty_owncloud: DNE
50
 
artful_owncloud: DNE
51
 
bionic_owncloud: DNE
52
 
devel_owncloud: DNE
53