Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Fedora: 2020:0820-0 Important: WordPress Security Release

opensuse
Calendar Grey February 15, 2020
Dist Opensuse Esm H88
OpenSUSE Security Patch for Nextcloud: Addresses 6 vulnerabilities deemed of moderate severity released. Updated packages are now accessible.
An update that fixes 6 vulnerabilities is now available.

Description

This update for nextcloud fixes the following issues:

Nextcloud was updated to 15.0.14:

- NC-SA-2020-002, CVE-2019-15613: workflow rules to depend their behaviour

on the file extension when checking file mimetypes (boo#1162766)

- NC-SA-2019-016, CVE-2019-15623: Exposure of Private Information caused

the server to send it's domain and user IDs to the Nextcloud Lookup

Server without any further data when the Lookup server is disabled

(boo#1162775)

- NC-SA-2019-015, CVE-2019-15624: Improper Input Validation allowed group

admins to create users with IDs of system folders (boo#1162776)

- NC-SA-2019-012, CVE-2020-8119: Improper authorization caused leaking of

previews and files when a file-drop share link is opened via the gallery

app (boo#1162781)

- NC-SA-2019-014, CVE-2020-8118: An authenticated server-side request

forgery allowed to detect local and remote services when adding a new

subscription in the calendar...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- SUSE Package Hub for SUSE Linux Enterprise 12:

zypper in -t patch openSUSE-2020-220=1

Package List

- SUSE Package Hub for SUSE Linux Enterprise 12 (noarch):

nextcloud-13.0.12-19.1

References

https://www.suse.com/security/cve/CVE-2019-15613.html

https://www.suse.com/security/cve/CVE-2019-15621.html

https://www.suse.com/security/cve/CVE-2019-15623.html

https://www.suse.com/security/cve/CVE-2019-15624.html

https://www.suse.com/security/cve/CVE-2020-8118.html

https://www.suse.com/security/cve/CVE-2020-8119.html

https://bugzilla.suse.com/1162766

https://bugzilla.suse.com/1162775

https://bugzilla.suse.com/1162776

https://bugzilla.suse.com/1162781

https://bugzilla.suse.com/1162782

https://bugzilla.suse.com/1162784

--

Announcement ID: openSUSE-SU-2020:0220-1
Rating: moderate
Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here