Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

openSUSE: 2023:0171-1 Important: Nextcloud Desktop HTML Injection Fix

opensuse
Calendar Grey July 10, 2023
Dist Opensuse Esm H88
Nextcloud-desktop has undergone a crucial security enhancement aimed at addressing HTML injection vulnerabilities and problems with TLS trust.
An update that fixes 5 vulnerabilities is now available

Description

This update for nextcloud-desktop fixes the following issues:

Update ot 3.8.0

- Resize WebView widget once the loginpage rendered

- Feature/secure file drop

- Check German translation for wrong wording

- L10n: Correct word

- Fix displaying of file details button for local syncfileitem activities

- Improve config upgrade warning dialog

- Only accept folder setup page if overrideLocalDir is set

- Update CHANGELOG.

- Prevent ShareModel crash from accessing bad pointers - Bugfix/init value for pointers - Log to stdout when built in Debug config

- Clean up account creation and deletion code

- L10n: Added dot to end of sentence

- L10n: Fixed grammar

- Fix "Create new folder" menu entries in settings not working correctly

on macOS

- Ci/clang tidy checks init variables

- Fix share dialog infinite loading

- Fix edit locally job not finding the user account: wrong user id

- Skip e2e...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP5:

zypper in -t patch openSUSE-2023-171=1

Package List

- openSUSE Backports SLE-15-SP5 (aarch64 x86_64):

libnextcloudsync-devel-3.8.0-bp155.2.3.1

libnextcloudsync0-3.8.0-bp155.2.3.1

nextcloud-desktop-3.8.0-bp155.2.3.1

nextcloud-desktop-dolphin-3.8.0-bp155.2.3.1

- openSUSE Backports SLE-15-SP5 (noarch):

caja-extension-nextcloud-3.8.0-bp155.2.3.1

cloudproviders-extension-nextcloud-3.8.0-bp155.2.3.1

nautilus-extension-nextcloud-3.8.0-bp155.2.3.1

nemo-extension-nextcloud-3.8.0-bp155.2.3.1

nextcloud-desktop-doc-3.8.0-bp155.2.3.1

nextcloud-desktop-lang-3.8.0-bp155.2.3.1

References

https://www.suse.com/security/cve/CVE-2022-39331.html

https://www.suse.com/security/cve/CVE-2022-39332.html

https://www.suse.com/security/cve/CVE-2022-39333.html

https://www.suse.com/security/cve/CVE-2022-39334.html

https://www.suse.com/security/cve/CVE-2023-23942.html

https://bugzilla.suse.com/1205798

https://bugzilla.suse.com/1205799

https://bugzilla.suse.com/1205800

https://bugzilla.suse.com/1205801

https://bugzilla.suse.com/1207976

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2023:0171-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP5 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here