PT-2008-3850 · Oracle+1 · Openoffice.Org+1

Tomas Hoger

·

Published

2008-06-13

·

Updated

2017-09-29

·

CVE-2008-2366

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: OpenOffice.org (OOo) version 1.1.x
Description: The issue is related to an untrusted search path vulnerability in a certain Red Hat build script for OpenOffice.org. This vulnerability allows local users to gain privileges via a malicious library in the current working directory. The problem arises from incorrect quoting of the ORIGIN symbol for use in the RPATH library path.
Recommendations: For OpenOffice.org version 1.1.x, consider restricting access to the build script to minimize the risk of exploitation until a fix is available. As a temporary workaround, ensure that the current working directory does not contain any malicious libraries.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2366
RHSA-2008:0538
RHSA-2008_0538

Affected Products

Openoffice.Org
Red Hat