First published: Wed Feb 04 2015(Updated: )
The SFTP external storage driver (files_external) in ownCloud Server before 6.0.5 validates the RSA Host key after login, which allows remote attackers to obtain sensitive information by sniffing the network.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ownCloud | <=6.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5341 is considered a medium severity vulnerability as it can lead to sensitive information disclosure.
To fix CVE-2014-5341, upgrade ownCloud Server to version 6.0.5 or later.
CVE-2014-5341 affects the SFTP external storage driver in ownCloud Server versions prior to 6.0.5.
Attackers can sniff the network traffic to obtain sensitive information due to improper host key validation.
CVE-2014-5341 was reported in 2014 and affects versions of ownCloud Server released before 6.0.5.