Boletines de Vulnerabilidades |
DSA-3363 owncloud-client - security update |
|
| Software afectado | Debian |
|
Johannes Kliemann discovered a vulnerability in ownCloud Desktop Client,the client-side of the ownCloud file sharing services. The vulnerabilityallows man-in-the-middle attacks in situations where the server is usingself-signed certificates and the connection is already established. Ifthe user in the client side manually distrusts the new certificate, thefile syncing will continue using the malicious server as valid. More info: https://www.debian.org/security/2015/dsa-3363 |
|














