Bug 1162764 - (CVE-2019-15616) VUL-1: CVE-2019-15616: nextcloud: Dangling remote share attempts allow a DNS pollution when running long
(CVE-2019-15616)
VUL-1: CVE-2019-15616: nextcloud: Dangling remote share attempts allow a DNS ...
Status: RESOLVED INVALID
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P4 - Low : Minor (vote)
: ---
Assigned To: Eric Schirra
Security Team bot
https://smash.suse.de/issue/252407/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-02-05 08:53 UTC by Robert Frohl
Modified: 2020-02-06 12:42 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2020-02-05 08:53:12 UTC
CVE-2019-15616

Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when
running long.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-15616
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15616
https://nextcloud.com/security/advisory/?id=NC-SA-2020-005
https://hackerone.com/reports/592864
Comment 1 Robert Frohl 2020-02-05 08:54:06 UTC
Fixed in Tumbleweed, but potentially still a problem in Leap 15.{1,2}
Comment 2 Eric Schirra 2020-02-05 09:07:15 UTC
What have this to do with nextcloud 15?
This is another branch.
Comment 3 Robert Frohl 2020-02-06 12:42:37 UTC
(In reply to Eric Schirra from comment #2)
> What have this to do with nextcloud 15?
> This is another branch.

Advisory states: 'Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.'

Which I missed when opening bugs, I agree that this is not valid.