Computer Security
[EN] securityvulns.ru no-pyccku


CVECVE-2015-4456
StatusCandidate
DescriptionownCloud Desktop Client before 1.8.2 does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, allows man-in-the-middle attackers to bypass the user's certificate distrust decision and obtain sensitive information by leveraging a self-signed certificate and a connection to a server using its own self-signed certificate.
PhaseAssigned (09.06.2015)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4456
ReferencesCONFIRM : https://github.com/owncloud/client/issues/3283
 CONFIRM : https://owncloud.org/security/advisory/?id=oc-sa-2...
SecurityVulns:owncloud client server spoofing
About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod