Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.902284
Category:General
Title:OpenOffice.org 'soffice' Directory Traversal Vulnerability - Windows
Summary:OpenOffice is prone to directory traversal vulnerabilities.
Description:Summary:
OpenOffice is prone to directory traversal vulnerabilities.

Vulnerability Insight:
The flaw is due to an error in 'soffice', which places a zero-length
directory name in the 'LD_LIBRARY_PATH'.

Vulnerability Impact:
Successful exploitation could allows local users to gain privileges via
a Trojan horse shared library in the current working directory.

Affected Software/OS:
OpenOffice Version 3.x to 3.2.0 on Windows

Solution:
Upgrade to OpenOffice Version 3.3.0 or later

CVSS Score:
6.9

CVSS Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-3689
1025004
http://www.securitytracker.com/id?1025004
40775
http://secunia.com/advisories/40775
42999
http://secunia.com/advisories/42999
43065
http://secunia.com/advisories/43065
43105
http://secunia.com/advisories/43105
46031
http://www.securityfocus.com/bid/46031
60799
http://secunia.com/advisories/60799
70716
http://osvdb.org/70716
ADV-2011-0230
http://www.vupen.com/english/advisories/2011/0230
ADV-2011-0232
http://www.vupen.com/english/advisories/2011/0232
ADV-2011-0279
http://www.vupen.com/english/advisories/2011/0279
DSA-2151
http://www.debian.org/security/2011/dsa-2151
GLSA-201408-19
http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml
MDVSA-2011:027
http://www.mandriva.com/security/advisories?name=MDVSA-2011:027
RHSA-2011:0182
http://www.redhat.com/support/errata/RHSA-2011-0182.html
USN-1056-1
http://ubuntu.com/usn/usn-1056-1
http://www.openoffice.org/security/cves/CVE-2010-3689.html
http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html
https://bugzilla.redhat.com/show_bug.cgi?id=641224
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.