PT-2008-3850 · Oracle+1 · Openoffice.Org+1
Tomas Hoger
·
Published
2008-06-13
·
Updated
2017-09-29
·
CVE-2008-2366
CVSS v2.0
4.4
Medium
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
OpenOffice.org (OOo) version 1.1.x
Description:
The issue is related to an untrusted search path vulnerability in a certain Red Hat build script for OpenOffice.org. This vulnerability allows local users to gain privileges via a malicious library in the current working directory. The problem arises from incorrect quoting of the ORIGIN symbol for use in the RPATH library path.
Recommendations:
For OpenOffice.org version 1.1.x, consider restricting access to the build script to minimize the risk of exploitation until a fix is available. As a temporary workaround, ensure that the current working directory does not contain any malicious libraries.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openoffice.Org
Red Hat