CVE-2015-3013

NameCVE-2015-3013
DescriptionownCloud Server before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allows remote authenticated users to bypass the file blacklist and upload arbitrary files via a file path with UTF-8 encoding, as demonstrated by uploading a .htaccess file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-3244-1

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
owncloudsourceexperimental7.0.5+dfsg-1
owncloudsourcejessie7.0.4+dfsg-4~deb8u1DSA-3244-1
owncloudsource(unstable)7.0.4+dfsg-3

Notes

https://owncloud.org/security/advisory/?id=oc-sa-2015-004

Search for package or bug name: Reporting problems