CVE-2024-46958

NameCVE-2024-46958
DescriptionIn Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1082041

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nextcloud-desktop (PTS)buster (security), buster, buster (lts)2.5.1-3+deb10u2vulnerable
bullseye (security), bullseye3.1.1-2+deb11u1fixed
bookworm3.7.3-1+deb12u1fixed
trixie3.13.2-2vulnerable
sid3.15.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nextcloud-desktopsourceexperimental3.14.1-1
nextcloud-desktopsourcebuster(unfixed)end-of-life
nextcloud-desktopsourcebullseye(not affected)
nextcloud-desktopsourcebookworm(not affected)
nextcloud-desktopsource(unstable)3.15.0-11082041

Notes

[bookworm] - nextcloud-desktop <not-affected> (Introduced in 3.13.1)
[bullseye] - nextcloud-desktop <not-affected> (Introduced in 3.13.1)
Fixed by: https://github.com/nextcloud/desktop/commit/a270756402d2a751da2ce41b0c53ee4dd934827c (master)
Fixed by: https://github.com/nextcloud/desktop/commit/13c73a5f39d35bbd187ced45aa06c9ab1d4fd5a0 (v3.13.4)
https://github.com/nextcloud/desktop/pull/6949
https://github.com/nextcloud/desktop/issues/6863

Search for package or bug name: Reporting problems