~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
Candidate: CVE-2013-0304
PublicDate: 2014-06-05
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0304
 http://www.openwall.com/lists/oss-security/2013/02/21
Description:
 ownCloud Server before 4.5.7 does not properly check ownership of
 calendars, which allows remote authenticated users to read arbitrary
 calendars via the calid parameter to /apps/calendar/export.php.  NOTE: this
 issue has been reported as a cross-site request forgery (CSRF)
 vulnerability, but due to lack of details, it is uncertain what the root
 cause is.
Ubuntu-Description:
Notes:
 mdeslaur> owncloud packages in Ubuntu are now empty
Bugs:
Priority: medium
Discovered-by:
Assigned-to:

Patches_owncloud:
upstream_owncloud: released (4.0.12, 4.5.7)
hardy_owncloud: DNE
lucid_owncloud: DNE
oneiric_owncloud: ignored (reached end-of-life)
precise_owncloud: not-affected
quantal_owncloud: ignored (reached end-of-life)
raring_owncloud: ignored (reached end-of-life)
saucy_owncloud: ignored (reached end-of-life)
trusty_owncloud: not-affected
utopic_owncloud: DNE
vivid_owncloud: DNE
wily_owncloud: DNE
devel_owncloud: DNE