CVE Vulnerabilities

CVE-2012-5057

Published: Jun 04, 2014 | Modified: Jun 04, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

CRLF injection vulnerability in ownCloud Server before 4.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the url path parameter.

Affected Software

Name Vendor Start Version End Version
Owncloud Owncloud * 4.0.7 (including)
Owncloud Owncloud 4.0.0 (including) 4.0.0 (including)
Owncloud Owncloud 4.0.1 (including) 4.0.1 (including)
Owncloud Owncloud 4.0.2 (including) 4.0.2 (including)
Owncloud Owncloud 4.0.3 (including) 4.0.3 (including)
Owncloud Owncloud 4.0.4 (including) 4.0.4 (including)
Owncloud Owncloud 4.0.5 (including) 4.0.5 (including)
Owncloud Owncloud 4.0.6 (including) 4.0.6 (including)
Owncloud Ubuntu upstream *

References