PT-2008-3850 · Oracle+1 · Openoffice.Org+1

Tomas Hoger

·

Publicado

2008-06-13

·

Atualizado

2017-09-29

·

CVE-2008-2366

CVSS v2.0

4.4

Média

VetorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: OpenOffice.org (OOo) version 1.1.x
Description: The issue is related to an untrusted search path vulnerability in a certain Red Hat build script for OpenOffice.org. This vulnerability allows local users to gain privileges via a malicious library in the current working directory. The problem arises from incorrect quoting of the ORIGIN symbol for use in the RPATH library path.
Recommendations: For OpenOffice.org version 1.1.x, consider restricting access to the build script to minimize the risk of exploitation until a fix is available. As a temporary workaround, ensure that the current working directory does not contain any malicious libraries.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2366
RHSA-2008:0538
RHSA-2008_0538

Produtos afetados

Openoffice.Org
Red Hat