Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-5341

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2014-5341
Last Modified 05 Feb 2015 10:20:08
Published 04 Feb 2015 01:59:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2014-5341

Summary

The SFTP external storage driver (files_external) in ownCloud Server before 6.0.5 validates the RSA Host key after login, which allows remote attackers to obtain sensitive information by sniffing the network.

Vulnerable Systems

Application

  • Owncloud 6.0.4


References

CONFIRM - https://owncloud.org/security/advisory/?id=oc-sa-2014-019


Last Updated: 27 May 2016 11:07:42