CVE-2015-7298

ownCloud Desktop Client before 2.0.1, when compiled with a Qt release after 5.3.x, does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which makes it easier for remote attackers to conduct man-in-the-middle (MITM) attacks by leveraging a server using a self-signed certificate.  NOTE: this vulnerability exists because of a partial CVE-2015-4456 regression.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.1 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
VendorProductVersion
owncloudowncloud_desktop_client
𝑥
≤ 2.0.0
qtqt
5.3.0
qtqt
5.4.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
owncloud-client
bookworm
2.11.0.8354+dfsg-1
fixed
jessie
not-affected
sid
5.2.1.13040+dfsg-3.0.1
fixed
trixie
5.2.1.13040+dfsg-3.0.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
owncloud-client
cosmic
not-affected
bionic
not-affected
artful
ignored
zesty
ignored
yakkety
ignored
xenial
not-affected
wily
ignored
vivid
ignored
trusty
dne
precise
dne