-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 05 Jan 2016 22:24:31 -0400 Source: owncloud Binary: owncloud Architecture: source all Version: 7.0.4+dfsg-4~deb8u4 Distribution: jessie Urgency: medium Maintainer: ownCloud for Debian maintainers <pkg-owncloud-maintainers@lists.alioth.debian.org> Changed-By: David Prévot <taffit@debian.org> Description: owncloud - cloud storage for files, music, contacts, calendars and many more Changes: owncloud (7.0.4+dfsg-4~deb8u4) jessie; urgency=medium . * Backport security fixes from 7.0.12, 8.0.10, and 8.0.9: - Reflected XSS in OCS provider discovery [oc-sa-2016-001] [CVE-2016-1498] - Disclosure of files that begin with \".v\" due to unchecked return value [oc-sa-2016-003] [CVE-2016-1500] - Information Exposure Through Directory Listing in the file scanner [oc-sa-2016-002] [CVE-2016-1499] - Full installation path disclosure through error message [oc-sa-2016-004] [CVE-2016-1501] Checksums-Sha1: 1d1062848bbbbc39af35b018baa55006a4d7f846 1755 owncloud_7.0.4+dfsg-4~deb8u4.dsc 4713a2f6511b515f655e8d36829af793309b43af 151928 owncloud_7.0.4+dfsg-4~deb8u4.debian.tar.xz bdc250c23ad81dd3c0137723909773d240861dd1 7538574 owncloud_7.0.4+dfsg-4~deb8u4_all.deb Checksums-Sha256: b4c525143663eee0b34bc18bd734a5236e9cccff2dfa45d5d0c976839edb3dc4 1755 owncloud_7.0.4+dfsg-4~deb8u4.dsc 02bdc20f4d55cce751e3e3927b44cdfc9d65c9670d59a213c09638dab257ee8b 151928 owncloud_7.0.4+dfsg-4~deb8u4.debian.tar.xz 754f970740d3b16000533203ead2e71c39d72795db13c76b150f350de63d6815 7538574 owncloud_7.0.4+dfsg-4~deb8u4_all.deb Files: af775b6bfa06d108b1fda9ba10f0fd59 1755 web extra owncloud_7.0.4+dfsg-4~deb8u4.dsc 81525ad213872630d157596d4844c742 151928 web extra owncloud_7.0.4+dfsg-4~deb8u4.debian.tar.xz 8248fa37932622cc46bd64718ab2d8f2 7538574 web extra owncloud_7.0.4+dfsg-4~deb8u4_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQEcBAEBCAAGBQJWjXOwAAoJEAWMHPlE9r08q8kIAI9Z+ZUkqZR9h/OX/iRHGzf3 TWhkpx7tgQsbwVluTU+fbFmaLHA1RzyyjOK1KL5MfcNfbVzc+fr0+wIAvbD68Vff rUypVpmXfzjaamzU06jdbIJAnM6J4nGA1IuYVrex2y8hFlN7R4YUBq7XcTk5iikt +LVPOmRYmT/Urlnl89A3CIS4yzkYceYQXOVZFe40KEfYBzTPEFS4u/N9/t4axY93 oSWfcz7YDNp/LgRlYx6PF+/OA6nEEWIc4DhybZ7BEDg3n4C4sv8A4vQsss/hSlev 1EuVWbHAOBda3oz3G1qzeEuLaItDQNXrQPbjCLxFWK4iLHi6XNmNlE8CxwPqJ7I= =MrNJ -----END PGP SIGNATURE-----