Bug 1226376 (CVE-2024-37885) - VUL-0: CVE-2024-37885: nextcloud-desktop: loading of arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the enviroment
Summary: VUL-0: CVE-2024-37885: nextcloud-desktop: loading of arbitrary code when star...
Status: NEW
Alias: CVE-2024-37885
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Atri Bhattacharya
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/410999/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-06-14 19:22 UTC by SMASH SMASH
Modified: 2024-06-14 20:15 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-06-14 19:22:42 UTC
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the enviroment. It is recommended that the Nextcloud Desktop client is upgraded to 3.12.0.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-37885
https://www.cve.org/CVERecord?id=CVE-2024-37885
https://github.com/nextcloud/desktop/pull/6378
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-4mf7-v63m-99p7
https://hackerone.com/reports/2307625
Comment 3 Atri Bhattacharya 2024-06-14 19:41:30 UTC
Seems to be limited to macOS only.