Security Advisory

Back to advisories

Memory Leak in OCUtil.dll library in Desktop client can lead to DoS (NC-SA-2020-034)

10th July 2020

Risk level: Low

CVSS v3 Base Score: 5.9 (AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H)

CWE: Denial of Service (CWE-400)

HackerOne report: 588562

Description

A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.

Affected Software

  • Nextcloud Desktop < 2.6.5 (CVE-2020-8229)

Action Taken

The error has been fixed.

Resolution

It is recommended that the Nextcloud Desktop Client is upgraded to 2.6.5.

Acknowledgements

The Nextcloud team thanks the following people for their research and responsible disclosure of the above advisory:

  • Cosmin Craciun - Finastra (cwaverst@gmail.com) - Vulnerability discovery and disclosure.

This advisory is licensed CC BY-SA 4.0.

You have javascript disabled. We tried to make sure the basics of our website work but some functionality will be missing.

This website is using cookies. By visiting you agree with our privacy policy. That's Fine