PT-2020-20036 · Openssl+2 · Openssl+2

Published

2020-08-10

·

Updated

2022-09-30

·

CVE-2020-8224

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nextcloud Desktop Client version 2.6.4
Description A code injection issue in the Nextcloud Desktop Client allowed the loading of arbitrary code when a malicious OpenSSL configuration was placed in a fixed directory.
Recommendations For Nextcloud Desktop Client version 2.6.4, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the fixed directory where the malicious OpenSSL configuration could be placed, to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2776
CVE-2020-8224

Affected Products

Alt Linux
Nextcloud Desktop Client
Openssl