A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.
The product does not properly control the allocation and maintenance of a limited resource.
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Link | Tags |
---|---|
https://hackerone.com/reports/588562 | third party advisory exploit |
https://nextcloud.com/security/advisory/?id=NC-SA-2020-034 | broken link vendor advisory |