Security Advisory

Back to advisories

Memory Leak in OCUtil.dll library in Desktop client can lead to DoS (NC-SA-2020-034)

10th July 2020

Risk level: Low

CVSS v3 Base Score: 5.9 (AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H)

CWE: Denial of Service (CWE-400)

HackerOne report: 588562

Description

A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.

Affected Software

Action Taken

The error has been fixed.

Resolution

It is recommended that the Nextcloud Desktop Client is upgraded to 2.6.5.

Acknowledgements

The Nextcloud team thanks the following people for their research and responsible disclosure of the above advisory:


This advisory is licensed CC BY-SA 4.0.