CVE-2014-2055: XEE
SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
Other sources
XEE issue that could expose local files or easily trigger a DOS attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2055?
CVE-2014-2055 is considered a critical vulnerability due to its ability to allow remote attackers to read arbitrary files and potentially cause a denial of service.
How do I fix CVE-2014-2055?
To fix CVE-2014-2055, update SabreDAV to version 1.7.11 or above, or apply the appropriate patches for affected ownCloud versions.
Which versions of SabreDAV are affected by CVE-2014-2055?
CVE-2014-2055 affects all SabreDAV versions prior to 1.7.11.
Can CVE-2014-2055 be exploited remotely?
Yes, CVE-2014-2055 can be exploited remotely through an XML External Entity (XXE) attack.
What software specifically is impacted by CVE-2014-2055?
CVE-2014-2055 impacts SabreDAV versions before 1.7.11 and ownCloud Server versions before 6.0.2.