[Pkg-owncloud-maintainers] Bug#804651: owncloud: renaming a folder can destroy all contained files

Cyrille Chépélov cch at transparencyrights.com
Tue Nov 10 09:10:43 UTC 2015


Subject: owncloud: Renaming a folder can destroy all contained files
Package: owncloud
Version: 7.0.4+dfsg-4~deb8u3
Severity: grave
X-Severity-explanation: can cause severe data loss, especially on 
non-technical users.

Dear Maintainer,


The following procedure can, depending on timing, cause immediate data loss:
   1. On a client, create a folder with subfolders and files within each 
folder level. The folder must be within folder shared to all other clients.
   2. Ensure this folder is replicated back to owncloud server and to 
all downstream clients (here: 3 Debian Linux clients, two Windows, 1 
Mac, all running the most recent version of owncloud-client for the 
respective platform)
   3. From a client's native file explorer (nautilus / Finder / 
Explorer), rename the folder made in #1
   4. Result: at the end of the rename and once all machines have sync'd 
back, some or all of the files contained within the folder have been 
permanently destroyed.

Thanks in advance.

     -- Cyrille

-- System Information:
Debian Release: 8.2
   APT prefers stable-updates
   APT policy: (500, 'stable-updates'), (500, 'oldstable-updates'), 
(500, 'stable'), (500, 'oldstable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.17-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=ANSI_X3.4-1968) 
(ignored: LC_ALL set to C)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages owncloud depends on:
ii  apache2 [httpd] 2.4.10-10+deb8u3
ii  apache2-mpm-event [httpd] 2.4.10-10+deb8u3
ii  apache2-mpm-worker [httpd] 2.4.10-10+deb8u3
ii  fonts-font-awesome                                  4.2.0~dfsg-1
ii  fonts-liberation                                    1.07.4-1
ii  fonts-linuxlibertine                                5.3.0-2
ii  fonts-lohit-deva                                    2.5.3-1
ii  fonts-sil-gentium-basic                             1.1-7
ii  fonts-wqy-microhei                                  0.2.0-beta-2
ii  libjs-chosen                                        0.9.11-2
ii  libjs-dojo-dojox 1.10.2+dfsg-1
ii  libjs-jcrop 0.9.12+dfsg-1
ii  libjs-jquery-minicolors                             1.2.1-1
ii  libjs-jquery-mousewheel                             10-1
ii  libjs-jquery-timepicker                             1.2-1
ii  libjs-mediaelement 2.15.1+dfsg-1
ii  libjs-pdf 1.0.907+dfsg-1+deb8u1
ii  libjs-underscore                                    1.7.0~dfsg-1
ii  libphp-phpmailer                                    5.2.9+dfsg-2
ii  owncloud-doc                                        0~20141208-2
ii  php-assetic                                         1.2.0-2
ii  php-doctrine-dbal                                   2.4.3-1
ii  php-getid3                                          1.9.8-3
ii  php-opencloud                                       1.10.0-2
ii  php-patchwork-utf8                                  1.1.25-1
ii  php-pear 5.6.14+dfsg-0+deb8u1
ii  php-pimple                                          1.1.1-1
ii  php-sabre-dav                                       1.8.10-2
ii  php-seclib                                          0.3.8-1
ii  php-symfony-class-loader [php-symfony-classloader] 2.3.21+dfsg-4+deb8u1
ii  php-symfony-classloader 2.3.21+dfsg-4+deb8u1
ii  php-symfony-console 2.3.21+dfsg-4+deb8u1
ii  php-symfony-routing 2.3.21+dfsg-4+deb8u1
ii  php5 5.6.14+dfsg-0+deb8u1
ii  php5-cli 5.6.14+dfsg-0+deb8u1
ii  php5-gd 5.6.14+dfsg-0+deb8u1
ii  php5-json                                           1.3.6-1
ii  php5-mysql 5.6.14+dfsg-0+deb8u1
ii  zendframework 1.12.9+dfsg-2+deb8u4

Versions of packages owncloud recommends:
ii  exim4                                      4.84-8
ii  exim4-daemon-light [mail-transport-agent]  4.84-8
ii  php-aws-sdk                                2.7.2-1
ii  php-crypt-blowfish                         1.1.0~RC2-4
ii  php-dropbox                                1.0.0-3
ii  php-google-api-php-client                  0.6.7-2
ii  php5-curl                                  5.6.14+dfsg-0+deb8u1
ii  php5-intl                                  5.6.14+dfsg-0+deb8u1
ii  php5-ldap                                  5.6.14+dfsg-0+deb8u1
ii  php5-mcrypt                                5.6.14+dfsg-0+deb8u1
ii  php5-xcache                                3.2.0-1
ii  smbclient                                  2:4.1.17+dfsg-2

Versions of packages owncloud suggests:
pn  libapache2-mod-xsendfile                 <none>
pn  libav-tools                              <none>
pn  libreoffice                              <none>
ii  mysql-server                             5.5.46-0+deb8u1
ii  mysql-server-5.5 [virtual-mysql-server]  5.5.46-0+deb8u1
pn  php5-imagick                             <none>
ii  postgresql                               9.4+165

-- Configuration Files:
/etc/owncloud/htaccess [Errno 13] Permission denied: 
u'/etc/owncloud/htaccess'

-- no debconf information



More information about the Pkg-owncloud-maintainers mailing list