Candidate: CVE-2012-4397 PublicDate: 2012-09-05 23:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4397 http://www.openwall.com/lists/oss-security/2012/09/01 Description: Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) calendar displayname to part.choosecalendar.rowfields.php or (2) part.choosecalendar.rowfields.shared.php in apps/calendar/templates/; or (3) unspecified vectors to apps/contacts/lib/vcard.php. Ubuntu-Description: Notes: mdeslaur> owncloud packages in Ubuntu are now empty Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_owncloud: upstream: https://github.com/owncloud/core/commit/00595351400523168e18a08e3ffa5c3b1e7c1f6e upstream: https://github.com/owncloud/core/commit/54a371700554ed21a5cb7db03126b6c95ae4cbd3 upstream_owncloud: released (4.0.1debian-1) hardy_owncloud: DNE lucid_owncloud: DNE natty_owncloud: ignored (reached end-of-life) oneiric_owncloud: ignored (reached end-of-life) precise_owncloud: not-affected quantal_owncloud: not-affected (4.0.6debian-0ubuntu1) raring_owncloud: not-affected (4.0.6debian-0ubuntu1) saucy_owncloud: not-affected (4.0.6debian-0ubuntu1) trusty_owncloud: not-affected (4.0.6debian-0ubuntu1) trusty/esm_owncloud: DNE (trusty was not-affected [4.0.6debian-0ubuntu1]) utopic_owncloud: DNE vivid_owncloud: DNE wily_owncloud: DNE devel_owncloud: DNE