[Secure-testing-team] Bug#800126: owncloud: CVE-2015-6500: Information exposure through directory listing

Salvatore Bonaccorso carnil at debian.org
Sun Sep 27 07:17:50 UTC 2015


Source: owncloud
Version: 7.0.4+dfsg-1
Severity: important
Tags: security patch upstream fixed-upstream

Hi David,

the following vulnerability was published for owncloud. Would
appreciate if you can double check (affected function which
checks/scans the directories is already present in 7.x, but upstream
advisory mentions only 8.x).

CVE-2015-6500[0]:
Information exposure through directory listing

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2015-6500
[1] https://owncloud.org/security/advisory/?id=oc-sa-2015-014
[2] https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2015-048.txt

Regards,
Salvatore



More information about the Secure-testing-team mailing list