The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.7.0, by trusting that the server will return a certificate that belongs to the keypair of the user, a malicious server could get the desktop client to encrypt files with a key known to the attacker. This issue is fixed in Nextcloud Desktop 3.7.0. No known workarounds are available.
{
"binaries": [
{
"binary_version": "2.6.2-1build1",
"binary_name": "caja-nextcloud"
},
{
"binary_version": "2.6.2-1build1",
"binary_name": "dolphin-nextcloud"
},
{
"binary_version": "2.6.2-1build1",
"binary_name": "libnextcloudsync-dev"
},
{
"binary_version": "2.6.2-1build1",
"binary_name": "libnextcloudsync0"
},
{
"binary_version": "2.6.2-1build1",
"binary_name": "nautilus-nextcloud"
},
{
"binary_version": "2.6.2-1build1",
"binary_name": "nemo-nextcloud"
},
{
"binary_version": "2.6.2-1build1",
"binary_name": "nextcloud-desktop"
},
{
"binary_version": "2.6.2-1build1",
"binary_name": "nextcloud-desktop-cmd"
},
{
"binary_version": "2.6.2-1build1",
"binary_name": "nextcloud-desktop-common"
},
{
"binary_version": "2.6.2-1build1",
"binary_name": "nextcloud-desktop-l10n"
}
]
}
{
"binaries": [
{
"binary_version": "3.4.2-1ubuntu1",
"binary_name": "caja-nextcloud"
},
{
"binary_version": "3.4.2-1ubuntu1",
"binary_name": "dolphin-nextcloud"
},
{
"binary_version": "3.4.2-1ubuntu1",
"binary_name": "libnextcloudsync-dev"
},
{
"binary_version": "3.4.2-1ubuntu1",
"binary_name": "libnextcloudsync0"
},
{
"binary_version": "3.4.2-1ubuntu1",
"binary_name": "nautilus-nextcloud"
},
{
"binary_version": "3.4.2-1ubuntu1",
"binary_name": "nemo-nextcloud"
},
{
"binary_version": "3.4.2-1ubuntu1",
"binary_name": "nextcloud-desktop"
},
{
"binary_version": "3.4.2-1ubuntu1",
"binary_name": "nextcloud-desktop-cmd"
},
{
"binary_version": "3.4.2-1ubuntu1",
"binary_name": "nextcloud-desktop-common"
},
{
"binary_version": "3.4.2-1ubuntu1",
"binary_name": "nextcloud-desktop-l10n"
}
]
}