CVE-2013-1941: Medium severity ownCloud ownCloud vulnerability
The installation routine in ownCloud Server before 4.0.14, 4.5.x before 4.5.9, and 5.0.x before 5.0.4 uses the time function to seed the generation of the PostgreSQL database user password, which makes it easier for remote attackers to guess the password via a brute force attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1941?
CVE-2013-1941 is classified as a medium severity vulnerability due to its ability to expose database user passwords to brute force attacks.
How do I fix CVE-2013-1941?
To fix CVE-2013-1941, upgrade to ownCloud Server version 4.0.14, 4.5.9, or 5.0.4 or later.
What versions of ownCloud are affected by CVE-2013-1941?
CVE-2013-1941 affects ownCloud Server versions before 4.0.14, 4.5.x before 4.5.9, and 5.0.x before 5.0.4.
Can CVE-2013-1941 be exploited remotely?
Yes, CVE-2013-1941 can be exploited by remote attackers to guess the PostgreSQL database user password.
What are the potential consequences of CVE-2013-1941?
The potential consequences of CVE-2013-1941 include unauthorized access to the PostgreSQL database and potential data exposure.