aboutsummaryrefslogtreecommitdiffstats
path: root/security/vuxml
diff options
context:
space:
mode:
authorculot <culot@FreeBSD.org>2013-06-12 05:03:38 +0800
committerculot <culot@FreeBSD.org>2013-06-12 05:03:38 +0800
commit986d230128e36e2b78322b4f58a4ded81f4726b3 (patch)
tree32fe9cc8c13f247a4af21440cdec23cc3f8473bb /security/vuxml
parentc358a9dc38fa78095104f1c58960da5007039486 (diff)
downloadfreebsd-ports-gnome-986d230128e36e2b78322b4f58a4ded81f4726b3.tar.gz
freebsd-ports-gnome-986d230128e36e2b78322b4f58a4ded81f4726b3.tar.zst
freebsd-ports-gnome-986d230128e36e2b78322b4f58a4ded81f4726b3.zip
- Document vulnerabilities in www/owncloud
Security: d7a43ee6-d2d5-11e2-9894-002590082ac6 Obtained from: http://owncloud.org/about/security/advisories/
Diffstat (limited to 'security/vuxml')
-rw-r--r--security/vuxml/vuln.xml62
1 files changed, 62 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index 238889c6ed36..aa9a6826275c 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -51,6 +51,68 @@ Note: Please add new entries to the beginning of this file.
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
+ <vuln vid="d7a43ee6-d2d5-11e2-9894-002590082ac6">
+ <topic>owncloud -- Multiple security vulnerabilities</topic>
+ <affects>
+ <package>
+ <name>owncloud</name>
+ <range><lt>5.0.7</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>The ownCloud development team reports:</p>
+ <blockquote cite="http://owncloud.org/about/security/advisories/">
+ <p>oC-SA-2013-019 / CVE-2013-2045: Multiple SQL Injections.
+ Credit to Mateusz Goik (aliantsoft.pl).</p>
+ <p>oC-SA-2013-020 / CVE-2013-[2039,2085]: Multiple directory traversals.
+ Credit to Mateusz Goik (aliantsoft.pl).</p>
+ <p>oC-SQ-2013-021 / CVE-2013-[2040-2042]: Multiple XSS vulnerabilities.
+ Credit to Mateusz Goik (aliantsoft.pl) and Kacper R. (http://devilteam.pl).</p>
+ <p>oC-SA-2013-022 / CVE-2013-2044: Open redirector.
+ Credit to Mateusz Goik (aliantsoft.pl).</p>
+ <p>oC-SA-2013-023 / CVE-2013-2047: Password autocompletion.</p>
+ <p>oC-SA-2013-024 / CVE-2013-2043: Privilege escalation in the calendar application.
+ Credit to Mateusz Goik (aliantsoft.pl).</p>
+ <p>oC-SA-2013-025 / CVE-2013-2048: Privilege escalation and CSRF in the API.</p>
+ <p>oC-SA-2013-026 / CVE-2013-2089: Incomplete blacklist vulnerability.</p>
+ <p>oC-SA-2013-027 / CVE-2013-2086: CSRF token leakage.</p>
+ <p>oC-SA-2013-028 / CVE-2013-[2149-2150]: Multiple XSS vulnerabilities.</p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <url>http://owncloud.org/about/security/advisories/oC-SA-2013-019/</url>
+ <url>http://owncloud.org/about/security/advisories/oC-SA-2013-020/</url>
+ <url>http://owncloud.org/about/security/advisories/oC-SA-2013-021/</url>
+ <url>http://owncloud.org/about/security/advisories/oC-SA-2013-022/</url>
+ <url>http://owncloud.org/about/security/advisories/oC-SA-2013-023/</url>
+ <url>http://owncloud.org/about/security/advisories/oC-SA-2013-024/</url>
+ <url>http://owncloud.org/about/security/advisories/oC-SA-2013-025/</url>
+ <url>http://owncloud.org/about/security/advisories/oC-SA-2013-026/</url>
+ <url>http://owncloud.org/about/security/advisories/oC-SA-2013-027/</url>
+ <url>http://owncloud.org/about/security/advisories/oC-SA-2013-028/</url>
+ <cvename>CVE-2013-2039</cvename>
+ <cvename>CVE-2013-2040</cvename>
+ <cvename>CVE-2013-2041</cvename>
+ <cvename>CVE-2013-2042</cvename>
+ <cvename>CVE-2013-2043</cvename>
+ <cvename>CVE-2013-2044</cvename>
+ <cvename>CVE-2013-2045</cvename>
+ <cvename>CVE-2013-2047</cvename>
+ <cvename>CVE-2013-2048</cvename>
+ <cvename>CVE-2013-2085</cvename>
+ <cvename>CVE-2013-2086</cvename>
+ <cvename>CVE-2013-2089</cvename>
+ <cvename>CVE-2013-2149</cvename>
+ <cvename>CVE-2013-2150</cvename>
+ </references>
+ <dates>
+ <discovery>2013-05-14</discovery>
+ <entry>2013-06-11</entry>
+ </dates>
+ </vuln>
+
<vuln vid="59e7163c-cf84-11e2-907b-0025905a4770">
<topic>php5 -- Heap based buffer overflow in quoted_printable_encode</topic>
<affects>