CVE-2014-4929
Publication date 20 August 2014
Last updated 24 July 2024
Ubuntu priority
Description
Directory traversal vulnerability in the routing component in ownCloud Server before 5.0.17 and 6.0.x before 6.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in a filename, related to index.php.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| owncloud | ||
| 14.04 LTS trusty | Not in release | |
Notes
References
Other references
- https://github.com/owncloud/security-advisories/blob/master/server/oc-sa-2014-018.json
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:140
- http://owncloud.org/security/advisory/?id=oc-sa-2014-018
- http://advisories.mageia.org/MGASA-2014-0301.html
- https://www.cve.org/CVERecord?id=CVE-2014-4929