CVE-2016-1499

NameCVE-2016-1499
DescriptionownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information from a directory listing and possibly cause a denial of service (CPU consumption) via the force parameter to index.php/apps/files/ajax/scan.php.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
owncloudsourceexperimental8.2.2~dfsg-1
owncloudsourcejessie7.0.4+dfsg-4~deb8u4
owncloudsource(unstable)7.0.12~dfsg-2

Notes

https://owncloud.org/security/advisory/?id=oc-sa-2016-002

Search for package or bug name: Reporting problems