Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-37885
HistoryJun 14, 2024 - 12:00 a.m.

CVE-2024-37885

2024-06-1400:00:00
ubuntu.com
ubuntu.com
7
nextcloud desktop client
macos
code injection
dyld_insert_libraries
upgrade
cve-2024-37885
nextcloud server

CVSS3

3.8

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L

AI Score

7.5

Confidence

Low

EPSS

0

Percentile

5.0%

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud
Server with your computer. A code injection in Nextcloud Desktop Client for
macOS allowed to load arbitrary code when starting the client with
DYLD_INSERT_LIBRARIES set in the enviroment. It is recommended that the
Nextcloud Desktop client is upgraded to 3.12.0.

Notes

Author Note
rodrigo-zaiden Only affects macOS

CVSS3

3.8

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L

AI Score

7.5

Confidence

Low

EPSS

0

Percentile

5.0%