[Pkg-owncloud-maintainers] Upstream short time support of owncloud-client

David Prévot taffit at debian.org
Sat Sep 5 19:08:07 UTC 2015


Hi Sandro and all,

According to upstream security page [1], “ownCloud Desktop Client”,
“1.0.x to 1.7.x”, are among the “Unsupported Product Versions”. Looks
like I missed the deprecation warning :/ (or maybe there wasn’t any, it
seems like upstream is sadly going the way to hide security issues: they
are not even mentioned in the changelog any more, nor in the release
announcement when they still issue one).

	1: https://owncloud.org/security/

Furthermore, 1.8.2 fixed CVE-2015-4456 [2], is the version currently in
Jessie affected? If so, can you please prepare a fixed version targeted
to Jessie?

	2: https://owncloud.org/security/advisory/?id=oc-sa-2015-009

Thanks in advance.

Regards

David
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 473 bytes
Desc: Digital signature
URL: <http://lists.alioth.debian.org/pipermail/pkg-owncloud-maintainers/attachments/20150905/d77dfd79/attachment.sig>


More information about the Pkg-owncloud-maintainers mailing list