PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5867 Owncloud CVE debrief

CVE-2017-5867 describes a denial-of-service issue in ownCloud Server where a remote authenticated user can trigger a server hang and logfile flooding by uploading or processing a one-bit BMP file. The issue affects multiple ownCloud release lines and is addressed by vendor-fixed versions.

Vendor
Owncloud
Product
Unknown
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-03-03
Original CVE updated
2026-05-13
Advisory published
2017-03-03
Advisory updated
2026-05-13

Who should care

ownCloud administrators, security teams, and operations staff running affected Server releases should care, especially where authenticated users can upload or process image files.

Technical summary

NVD describes the flaw as CVSS 3.0 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, with CWE-400 as the weakness category. A remote authenticated attacker can cause availability impact through a one-bit BMP file, leading to server hang behavior and excessive log generation. Affected versions listed in the record include ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3.

Defensive priority

Medium-high for exposed ownCloud deployments: patch promptly if authenticated users can submit files or if availability is operationally critical.

Recommended defensive actions

  • Upgrade ownCloud Server to 8.1.11 or later, 8.2.9 or later, 9.0.7 or later, or 9.1.3 or later, as applicable.
  • Review any workflows that accept user-supplied BMP files and restrict or isolate them where possible.
  • Monitor ownCloud logs and service health for abnormal logfile growth or hang conditions.
  • Inventory deployed ownCloud versions to confirm no affected release remains in production.

Evidence notes

The CVE description states that ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to cause a denial of service via a one bit BMP file. NVD classifies the issue as CVSS 3.0 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H and CWE-400, and includes a vendor advisory reference from ownCloud.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5867 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5867

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5867 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5867

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.