DescriptionDhananjay Arunesh
2020-08-24 07:48:33 UTC
A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.
References:
https://hackerone.com/reports/380102
Comment 1Dhananjay Arunesh
2020-08-24 08:05:54 UTC
Comment 2Dhananjay Arunesh
2020-08-24 08:06:06 UTC
Created nextcloud tracking bugs for this issue:
Affects: epel-7 [bug 1871748]
Affects: fedora-all [bug 1871746]
Created nextcloud-client tracking bugs for this issue:
Affects: epel-7 [bug 1871749]
Affects: fedora-all [bug 1871747]
Comment 3Product Security DevOps Team
2020-08-24 09:15:21 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.