PatchSiren cyber security CVE debrief
CVE-2017-5867 Owncloud CVE debrief
CVE-2017-5867 describes a denial-of-service issue in ownCloud Server where a remote authenticated user can trigger a server hang and logfile flooding by uploading or processing a one-bit BMP file. The issue affects multiple ownCloud release lines and is addressed by vendor-fixed versions.
- Vendor
- Owncloud
- Product
- Unknown
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-03
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-03
- Advisory updated
- 2026-05-13
Who should care
ownCloud administrators, security teams, and operations staff running affected Server releases should care, especially where authenticated users can upload or process image files.
Technical summary
NVD describes the flaw as CVSS 3.0 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, with CWE-400 as the weakness category. A remote authenticated attacker can cause availability impact through a one-bit BMP file, leading to server hang behavior and excessive log generation. Affected versions listed in the record include ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3.
Defensive priority
Medium-high for exposed ownCloud deployments: patch promptly if authenticated users can submit files or if availability is operationally critical.
Recommended defensive actions
- Upgrade ownCloud Server to 8.1.11 or later, 8.2.9 or later, 9.0.7 or later, or 9.1.3 or later, as applicable.
- Review any workflows that accept user-supplied BMP files and restrict or isolate them where possible.
- Monitor ownCloud logs and service health for abnormal logfile growth or hang conditions.
- Inventory deployed ownCloud versions to confirm no affected release remains in production.
Evidence notes
The CVE description states that ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to cause a denial of service via a one bit BMP file. NVD classifies the issue as CVSS 3.0 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H and CWE-400, and includes a vendor advisory reference from ownCloud.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5867 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5867
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5867 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5867
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.