Description
The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, which allows remote attackers to cause a denial of service (infinite loop and log file consumption) via crafted endpoint file names.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-3373-1 | owncloud security update |
EUVD |
EUVD-2015-4734 | The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, which allows remote attackers to cause a denial of service (infinite loop and log file consumption) via crafted endpoint file names. |
References
History
Mon, 31 Mar 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Owncloud owncloud Server
|
|
| CPEs | cpe:2.3:a:owncloud:owncloud:7.0.1:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:7.0.2:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:7.0.3:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:7.0.4:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:7.0.5:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:8.0.0:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:8.0.2:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:8.0.3:*:*:*:*:*:*:* |
cpe:2.3:a:owncloud:owncloud_server:7.0.0:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:7.0.1:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:7.0.2:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:7.0.3:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:7.0.4:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:7.0.5:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:8.0.0:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:8.0.2:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:8.0.3:*:*:*:*:*:*:* |
| Vendors & Products |
Owncloud owncloud Server
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T06:25:21.446Z
Reserved: 2015-06-22T00:00:00.000Z
Link: CVE-2015-4717
No data.
Status : Deferred
Published: 2015-10-21T18:59:01.517
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-4717
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD