CVE-2015-4717: High severity owncloud vulnerability
The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $GET parameters cast by PHP to an array, which allows remote attackers to cause a denial of service (infinite loop and log file consumption) via crafted endpoint file names.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4717?
CVE-2015-4717 is considered a moderate severity vulnerability due to its ability to cause a denial of service.
How do I fix CVE-2015-4717?
To mitigate CVE-2015-4717, upgrade ownCloud Server to version 6.0.8, 7.0.6, or 8.0.4 or later.
What versions of ownCloud are affected by CVE-2015-4717?
CVE-2015-4717 affects ownCloud Server versions prior to 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4.
Can CVE-2015-4717 be exploited remotely?
Yes, CVE-2015-4717 can be exploited remotely by attackers to trigger a denial of service.
What are the consequences of CVE-2015-4717?
The consequence of CVE-2015-4717 includes potential infinite loops and excessive log file consumption leading to denial of service.