Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

openSUSE 15.2: 2021:0577-1 Important: Nextcloud Desktop Resource Injection

opensuse
Calendar Grey April 19, 2021
Dist Opensuse Esm H88
A crucial patch for the openSUSE nextcloud-client has been made available, resolving an issue related to resource injection vulnerabilities.
An update that fixes one vulnerability is now available

Description

This update for nextcloud-desktop fixes the following issues:

nextcloud-desktop was updated to 3.1.3:

- desktop#2884 [stable-3.1] Add support for Hirsute

- desktop#2920 [stable-3.1] Validate sensitive URLs to onle allow http(s)

schemes.

- desktop#2926 [stable-3.1] Validate the providers ssl certificate

- desktop#2939 Bump release to 3.1.3

This also fix security issues:

- (boo#1184770, CVE-2021-22879, NC-SA-2021-008 , CWE-99)

Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource

injection by way of missing validation of URLs, allowing a malicious

server to execute remote commands. User interaction is needed for

exploitation.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-577=1

Package List

- openSUSE Leap 15.2 (x86_64):

libnextcloudsync-devel-3.1.3-lp152.2.6.1

libnextcloudsync0-3.1.3-lp152.2.6.1

libnextcloudsync0-debuginfo-3.1.3-lp152.2.6.1

nextcloud-desktop-3.1.3-lp152.2.6.1

nextcloud-desktop-debuginfo-3.1.3-lp152.2.6.1

nextcloud-desktop-debugsource-3.1.3-lp152.2.6.1

nextcloud-desktop-dolphin-3.1.3-lp152.2.6.1

nextcloud-desktop-dolphin-debuginfo-3.1.3-lp152.2.6.1

- openSUSE Leap 15.2 (noarch):

caja-extension-nextcloud-3.1.3-lp152.2.6.1

nautilus-extension-nextcloud-3.1.3-lp152.2.6.1

nemo-extension-nextcloud-3.1.3-lp152.2.6.1

nextcloud-desktop-doc-3.1.3-lp152.2.6.1

nextcloud-desktop-lang-3.1.3-lp152.2.6.1

References

https://www.suse.com/security/cve/CVE-2021-22879.html

https://bugzilla.suse.com/1184770

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:0577-1
Rating: important
Affected Products: openSUSE Leap 15.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here