CVE-2013-1939

NameCVE-2013-1939
DescriptionThe HTML\Browser plugin in SabreDAV before 1.6.9, 1.7.x before 1.7.7, and 1.8.x before 1.8.5, as used in ownCloud, when running on Windows, does not properly check path separators in the base path, which allows remote attackers to read arbitrary files via a \ (backslash) character.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php-sabredav (PTS)bullseye1.8.12-9fixed
bookworm, sid1.8.12-10fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
owncloudsource(unstable)(not affected)
php-sabredavsource(unstable)(not affected)

Notes

- owncloud <not-affected> (Windows version only)
- php-sabredav <not-affected> (running in Windows hosts)
http://owncloud.org/about/security/advisories/oC-SA-2013-016/

Search for package or bug name: Reporting problems