While it's a good finding that even in this specific scenario the crypto-module is screwed up, I think an even bigger problem is that most people hosting owncloud either don't know or care about all threats not covered by this scenario.
I heard stuff like "Owncloud has crypto, so it must be secure." from people hosting owncloud on server they didn't have much control (especially physically) about. It's not only the "malicious server operator" but everyone with administrative access (legitimate or not) to this server.
But unfortunately I don't know a selfhosted easy-to-install-and-use alternative with strong client-side encryption, which boils down to: Dropbox (or any other cloud storage provider) with client-side encryption of your own choice is more secure than owncloud with only the crypto-module.