Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-5607

Опубликовано: 18 дек. 2012
Источник: debian

Описание

The "Lost Password" reset functionality in ownCloud before 4.0.9 and 4.5.0 does not properly check the security token, which allows remote attackers to change an accounts password via unspecified vectors related to a "Remote Timing Attack."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
owncloudfixed4.0.8debian-1.1package
owncloudfixed4.0.4debian2-3.1wheezypackage

Примечания

  • https://www.openwall.com/lists/oss-security/2012/11/30/2

Связанные уязвимости

ubuntu
около 13 лет назад

The "Lost Password" reset functionality in ownCloud before 4.0.9 and 4.5.0 does not properly check the security token, which allows remote attackers to change an accounts password via unspecified vectors related to a "Remote Timing Attack."

nvd
около 13 лет назад

The "Lost Password" reset functionality in ownCloud before 4.0.9 and 4.5.0 does not properly check the security token, which allows remote attackers to change an accounts password via unspecified vectors related to a "Remote Timing Attack."

github
больше 3 лет назад

The "Lost Password" reset functionality in ownCloud before 4.0.9 and 4.5.0 does not properly check the security token, which allows remote attackers to change an accounts password via unspecified vectors related to a "Remote Timing Attack."