openSUSE Security Update: Security update for nextcloud

Announcement ID:    openSUSE-SU-2020:0667-1
Rating:             moderate
References:         #1084320 #1171572 #1171579 
Cross-References:   CVE-2020-8154 CVE-2020-8155
Affected Products:
                    SUSE Package Hub for SUSE Linux Enterprise 12

   An update that solves two vulnerabilities and has one
   errata is now available.


   This update for nextcloud to 18.0.4 fixes the following issues:

   Security issues fixed:

   - CVE-2020-8154: Fixed an XSS vulnerability when opening malicious PDFs
     (NC-SA-2020-018 boo#1171579).
   - CVE-2020-8155: Fixed a direct object reference vulnerability that
     allowed attackers to remotely wipe devices of other users
     (NC-SA-2020-019 boo#1171572).

Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - SUSE Package Hub for SUSE Linux Enterprise 12:

      zypper in -t patch openSUSE-2020-667=1

Package List:

   - SUSE Package Hub for SUSE Linux Enterprise 12 (noarch):