Bug 11798 - owncloud new security issue fixed in 5.0.13 (CVE-2013-6403)
Summary: owncloud new security issue fixed in 5.0.13 (CVE-2013-6403)
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 3
Hardware: i586 Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/576924/
Whiteboard: has_procedure mga3-64-ok mga3-32-ok
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2013-11-27 16:55 CET by David Walser
Modified: 2013-12-13 17:42 CET (History)
4 users (show)

See Also:
Source RPM: owncloud-5.0.9-1.mga3.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2013-11-27 16:55:24 CET
Upstream has released version 5.0.13 on November 8:
http://mail.kde.org/pipermail/owncloud/2013-November/011024.html

It says there's a security fix in it, though no details seem to be available.

Obviously I'm not sure if the issue also affects Cauldron, but we have 6.0.0 beta 2 there, and beta 5 is currently available, and the release candidate is supposed to be out today, so it should probably be updated there too.

Reproducible: 

Steps to Reproduce:
Comment 1 David Walser 2013-11-27 16:57:30 CET
The upstream changelog actually does say something about this:
"SECURITY: Fix a possible security bypass on admin page under certain circumstances and MariaDB."

http://owncloud.org/changelog/
Comment 2 Oden Eriksson 2013-11-28 11:48:47 CET
"Donât write user passwords into logfile" :-)

CC: (none) => oe

Comment 3 Oden Eriksson 2013-11-28 16:12:20 CET
http://www.openwall.com/lists/oss-security/2013/11/28/6

Summary: owncloud new security issue fixed in 5.0.13 => owncloud new security issue fixed in 5.0.13 (CVE-2013-6403)

Comment 4 David Walser 2013-11-28 16:41:45 CET
Package updated to beta5 in Cauldron, but now RC1 is out:
http://mail.kde.org/pipermail/owncloud/2013-November/011143.html
Comment 5 Nicolas Lécureuil 2013-12-11 22:06:01 CET
on the BS right now
Comment 6 David Walser 2013-12-11 22:23:17 CET
Thanks Nicolas!

RedHat has rated this as a high severity issue:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-6403

Advisory:
========================

Updated owncloud package fixes security vulnerability:

Possible security bypass on admin page under certain circumstances and MariaDB
(CVE-2013-6403).

The owncloud package has been updated to version 5.0.13, fixing this and many
other issues.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6403
http://www.openwall.com/lists/oss-security/2013/11/28/6
http://owncloud.org/changelog/
========================

Updated packages in core/updates_testing:
========================
owncloud-5.0.13-1.mga3

from owncloud-5.0.13-1.mga3.src.rpm

CC: (none) => mageia
Assignee: mageia => qa-bugs
Severity: normal => critical

Comment 7 claire robinson 2013-12-12 15:02:39 CET
Testing complete mga3 64

As the cve affects mariadb rather than the default sqlite, installed owncloud with php-pdo_mysql and configured to use mariadb.

Created user & database owncloud with password owncloud on localhost and opened http://localhost/owncloud in a browser. The databse configuration becomes visible if 'Advanced' is clicked when configuring the admin user. Selected mysql and entered the database details there.

Logged in, uploaded some files and then checked after installing the update.

It upgraded it's database OK and no issues noted.

After uninstalling, removed the old config/data etc with 
rm -rf /usr/share/owncloud

Whiteboard: (none) => has_procedure mga3-64-ok

Comment 8 claire robinson 2013-12-12 15:26:15 CET
Testing complete mga3 32

Advisory uploaded. Validating.

Could sysadmin please push from 3 core/updates_testing to updates

Thanks!

Keywords: (none) => validated_update
Whiteboard: has_procedure mga3-64-ok => has_procedure mga3-64-ok mga3-32-ok
CC: (none) => sysadmin-bugs

Comment 9 Thomas Backlund 2013-12-12 23:25:07 CET
Update pushed:
http://advisories.mageia.org/MGASA-2013-0367.html

Status: NEW => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED

David Walser 2013-12-13 17:42:20 CET

URL: (none) => http://lwn.net/Vulnerabilities/576924/


Note You need to log in before you can comment on or make changes to this bug.