CVE-2012-5607

NameCVE-2012-5607
DescriptionThe "Lost Password" reset functionality in ownCloud before 4.0.9 and 4.5.0 does not properly check the security token, which allows remote attackers to change an accounts password via unspecified vectors related to a "Remote Timing Attack."
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs693990

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
owncloudsourcewheezy4.0.4debian2-3.1
owncloudsource(unstable)4.0.8debian-1.1693990

Notes

https://www.openwall.com/lists/oss-security/2012/11/30/2

Search for package or bug name: Reporting problems