Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 4974-1] nextcloud-desktop security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 4974-1] nextcloud-desktop security update


Chronologisch Thread 
  • From: Moritz Muehlenhoff <jmm AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 4974-1] nextcloud-desktop security update
  • Date: Sun, 19 Sep 2021 10:35:13 +0000
  • Authentication-results: mail02.piratenpartei.de; dkim=none; spf=none (mail02.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
  • List-archive: https://lists.debian.org/msgid-search/20210919103513.GA28645 AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From: Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=g2xPVbYAiayIzN357qIbDaC+L6nyws+jFyD7FG7DJp0=; b=Kk 53ntswh19RWrAI6MLjNvKS+rjRuQbOLoWYcBqMcYw6+tsEk00IYpfxTeG9SdBAM2mc0Ktfv6GAA8x AUsOm2bFFIy2zZGT/o29rte6p/TTPDDs0hAkjqSBfFDEqY7bwkYKaCwinQFmdMGzBS9XqaBLhdukq TpTXUJE/X9bOW8lh/Eww/s7aQmAUeV/Okg6fJqLetTWs2F5y9DbwrSPPCb5zaHLqJwWU7QzM8ALo6 VvABsXGNb2kFBgFvtErJyBj8/zncB3ZvUYRxfD1kNVhCnONUzlEWydZug1Lo0hwRFL1ati8ZVzGPL 6QZEQg27qkQoqkOQAybL2OrZBaRMZYMg==;
  • Old-return-path: <jmm AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Sun, 19 Sep 2021 10:35:32 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <rDly9nli4WH.A.TyF.0JxRhB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4974-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
September 19, 2021 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : nextcloud-desktop
CVE ID : CVE-2021-22895 CVE-2021-32728
Debian Bug : 989846

Two vulnerabilities were discovered in the Nextcloud desktop client,
which could result in information disclosure.

For the oldstable distribution (buster), these problems have been fixed
in version 2.5.1-3+deb10u2.

For the stable distribution (bullseye), these problems have been fixed in
version 3.1.1-2+deb11u1.

We recommend that you upgrade your nextcloud-desktop packages.

For the detailed security status of nextcloud-desktop please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/nextcloud-desktop

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmFHEiQACgkQEMKTtsN8
TjaJkA/8COhQnHhiPwIjfSnnhSde4nDsbu47p1d6cgCehv++6IY4KQnAjNfJ7q4W
0wkgHEiSPmUqLR1mQveURJaDo8mLkEgEF9oatkrW1z2Xp1HCzQX/PBGc9Ca40ycH
JEUuFAIef/wX4Sv0G/49fa2zDWCK06g6gVu8J/r7b256iXQoiUQqaxm8cpqmhHy6
TlV2M5mRUUaM4eYkvzZAUoWm8Co56QVUXsM64EH5aqfCx1kBMrXEgXRiPKwsvuWI
uhmLXm5nFCkJhpqyQHApJhkNIrhPlCJdee0TLbh88rznas1UGkGXmcWFxpeqgJPi
N1gOug+zKxaR9nJAi4fcY6F8PNPzrnUmF6MQyd9ZUyYLQwuYj2VslknywKqH6Wyc
vV2WrgL+5ZLJ6hNQqBeELCLFVfnPxQWiVEgOedjmCJj82/l2bB3t18eetc0VF6RD
Vr25NW0zlNqDRuA9N5YkFZYKQrIYlaFOe43RAn8WTvBY/oAb7WUuf1kpfdIc6VbK
Gz8Cl93ugm13FxJZsdiV6ZTSMn3xOdIGVveAEIY984W/TDjZCzD0hqBoqlVtL9SG
fOXj1C+DkxN9iTPRaa4gyx8vQIg2k1hldiNsCWEgaaNzlwCIjtwHcK8S5yXqhqaj
8rWoVUmPQOqIjMnYgtLkN5V2P7dvq4JA0NHvb5wLg6OV1ElfQTA=
=r3kp
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 4974-1] nextcloud-desktop security update, Moritz Muehlenhoff, 19.09.2021

Archiv bereitgestellt durch MHonArc 2.6.24.

Seitenanfang