~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
Candidate: CVE-2012-2270
PublicDate: 2012-04-20
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2270
 http://www.tele-consulting.com/advisories/TC-SA-2012-01.txt
 http://secunia.com/advisories/48850
Description:
 Open redirect vulnerability in index.php (aka the Login Page) in ownCloud
 before 3.0.3 allows remote attackers to redirect users to arbitrary web
 sites and conduct phishing attacks via a URL in the redirect_url parameter.
Ubuntu-Description:
Notes:
 mdeslaur> owncloud packages in Ubuntu are now empty
Bugs:
 https://bugs.launchpad.net/ubuntu/+source/owncloud/+bug/1004379
Priority: medium
Discovered-by:
Assigned-to:

Patches_owncloud:
upstream_owncloud: released (3.0.3)
hardy_owncloud: DNE
lucid_owncloud: DNE
natty_owncloud: ignored (reached end-of-life)
oneiric_owncloud: ignored (reached end-of-life)
precise_owncloud: not-affected
quantal_owncloud: not-affected (4.0.7debian-1ubuntu1)
raring_owncloud: not-affected
saucy_owncloud: not-affected
trusty_owncloud: not-affected
utopic_owncloud: DNE
vivid_owncloud: DNE
wily_owncloud: DNE
devel_owncloud: DNE