Two flaws were reported as fixed in ownCloud 4.5.10: * XSS vulnerability in MediaElement.js (oC-SA-2013-017) [1] * Privilege escalation in the contacts application (oC-SA-2013-018) The XSS issue ([1]) has been assigned CVE-2013-1967 [3]. The second issue has not yet been assigned a CVE. [1] http://owncloud.org/about/security/advisories/oC-SA-2013-017/ [2] http://owncloud.org/about/security/advisories/oC-SA-2013-018/ [3] http://seclists.org/oss-sec/2013/q2/111
Created owncloud tracking bugs for this issue Affects: fedora-18 [bug 955308] Affects: epel-6 [bug 955309]
In fact, issue [2] was assigned CVE-2013-1963 here: http://seclists.org/oss-sec/2013/q2/133
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.