Описание
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | not-affected | |
hardy | DNE | |
karmic | DNE | |
lucid | DNE | |
maverick | DNE | |
upstream | released | 3.3 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | ignored | end of life |
devel | DNE | |
hardy | released | 1:2.4.1-1ubuntu2.5 |
karmic | released | 1:3.1.1-5ubuntu1.3 |
lucid | released | 1:3.2.0-7ubuntu4.2 |
maverick | released | 1:3.2.1-7ubuntu1.1 |
upstream | released | 3.3 |
Показывать по
EPSS
6.9 Medium
CVSS2
Связанные уязвимости
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length di ...
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Уязвимость переменной среды LD_LIBRARY_PATH офисных программ Apache OpenOffice, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным, вызвать отказ в обслуживании или оказать воздействие на целостность данных
EPSS
6.9 Medium
CVSS2