PT-2017-9018 · Apache · Apache Openoffice+1
Publicado
2017-11-13
·
Atualizado
2017-11-29
·
CVE-2016-6803
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache OpenOffice versions prior to 4.1.3
Description
The issue is related to an "unquoted Windows search path vulnerability" in the installer for Windows. This vulnerability can be exploited if the system has previously been infected with a Trojan Horse application or if a user is running with administrative privileges. The vulnerability acts as a delayed trigger for the exploit when an installer with the unquoted search path vulnerability is present.
Recommendations
For versions prior to 4.1.3, update to version 4.1.3 or later to resolve the issue.
Correção
Untrusted Search Path
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Openoffice
Openoffice