First published: Thu Mar 01 2018(Updated: )
The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrade.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =42.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9286 is considered a high-severity vulnerability due to its potential for privilege escalation.
To fix CVE-2017-9286, update your NextCloud package to the latest secure version available for openSUSE.
CVE-2017-9286 affects users of NextCloud packaged in openSUSE Leap 42.3.
The impact of CVE-2017-9286 involves possible privilege escalation from wwwrun user to root during package upgrades.
CVE-2017-9286 was disclosed in October 2017.