CVE-2015-3013

NameCVE-2015-3013
DescriptionownCloud Server before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allows remote authenticated users to bypass the file blacklist and upload arbitrary files via a file path with UTF-8 encoding, as demonstrated by uploading a .htaccess file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-3244-1
NVD severitymedium (attack range: remote)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
owncloudsource(unstable)7.0.4+dfsg-3medium
owncloudsourceexperimental7.0.5+dfsg-1medium
owncloudsourcejessie7.0.4+dfsg-4~deb8u1mediumDSA-3244-1

Notes

https://owncloud.org/security/advisory/?id=oc-sa-2015-004

Search for package or bug name: Reporting problems