CVE-2014-5341: Infoleak
Published Feb 4, 2015
·Updated
The SFTP external storage driver (filesexternal) in ownCloud Server before 6.0.5 validates the RSA Host key after login, which allows remote attackers to obtain sensitive information by sniffing the network.
Affected Software
1 affected component
ownCloud ownCloud<=6.0.4
Event History
Feb 4, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5341?
CVE-2014-5341 is considered a medium severity vulnerability as it can lead to sensitive information disclosure.
2
How do I fix CVE-2014-5341?
To fix CVE-2014-5341, upgrade ownCloud Server to version 6.0.5 or later.
3
What does CVE-2014-5341 affect?
CVE-2014-5341 affects the SFTP external storage driver in ownCloud Server versions prior to 6.0.5.
4
What can attackers do with CVE-2014-5341?
Attackers can sniff the network traffic to obtain sensitive information due to improper host key validation.
5
When was CVE-2014-5341 reported?
CVE-2014-5341 was reported in 2014 and affects versions of ownCloud Server released before 6.0.5.