~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
Candidate: CVE-2012-4391
PublicDate: 2012-09-05
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4391
 http://www.openwall.com/lists/oss-security/2012/09/01
Description:
 Cross-site request forgery (CSRF) vulnerability in core/ajax/appconfig.php
 in ownCloud before 4.0.7 allows remote attackers to hijack the
 authentication of administrators for requests that edit the app
 configurations.
Ubuntu-Description:
Notes:
 mdeslaur> owncloud packages in Ubuntu are now empty
Bugs:
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=686567
Priority: medium
Discovered-by:
Assigned-to:

Patches_owncloud:
 upstream: https://github.com/owncloud/core/commit/5192eecce239a0b7ade1e60a6cf03075e5cfc188
upstream_owncloud: released (4.0.7debian-1)
hardy_owncloud: DNE
lucid_owncloud: DNE
natty_owncloud: ignored (reached end-of-life)
oneiric_owncloud: ignored (reached end-of-life)
precise_owncloud: not-affected
quantal_owncloud: not-affected (4.0.7debian-1ubuntu1)
raring_owncloud: not-affected (4.0.7debian-1ubuntu1)
saucy_owncloud: not-affected (4.0.7debian-1ubuntu1)
trusty_owncloud: not-affected (4.0.7debian-1ubuntu1)
utopic_owncloud: DNE
vivid_owncloud: DNE
wily_owncloud: DNE
devel_owncloud: DNE