Input validation error in Nextcloud iOS App - CVE-2012-3923

 

Input validation error in Nextcloud iOS App - CVE-2012-3923

Published: September 16, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU43508
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2012-3923
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Nextcloud
Affected software:
Nextcloud iOS App

Detailed vulnerability description

The vulnerability allows a remote #AU# to perform service disruption.

The SSLVPN implementation in Cisco IOS 12.4, 15.0, 15.1, and 15.2, when DTLS is not enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP over ATM (PPPoA) interface, aka Bug ID CSCte41827.


How to mitigate CVE-2012-3923

Install update from vendor's website.

Sources