Red Hat Enterprise Linux OpenOffice Insecure Library Path Local Privilege Escalation Vulnerability
BID:29695
Info
Red Hat Enterprise Linux OpenOffice Insecure Library Path Local Privilege Escalation Vulnerability
| Bugtraq ID: | 29695 |
| Class: | Design Error |
| CVE: |
CVE-2008-2366 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 13 2008 12:00AM |
| Updated: | Jun 13 2008 10:12PM |
| Credit: | This issue was disclosed in Red Hat security advisory RHSA-2008:0538-7. |
| Vulnerable: |
Redhat OpenOffice.org 1.1.5 Redhat OpenOffice.org 1.1.2 Redhat OpenOffice.org 1.1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Desktop 4.0 Redhat Desktop 3.0 |
| Not Vulnerable: |
Redhat OpenOffice.org 1.1.5 -10.6.0.5 Redhat OpenOffice.org 1.1.2 -42.2.0 |
Discussion
Red Hat Enterprise Linux OpenOffice Insecure Library Path Local Privilege Escalation Vulnerability
Red Hat Enterprise Linux OpenOffice packages are prone to a local privilege-escalation vulnerability because they were built with insecure library search paths.
Exploiting this issue allows local attackers to execute arbitrary code with the privileges of the user running the affected application.
OpenOffice 1.1.x built and shipped with Red Hat Enterprise Linux 3 and 4 are affected.
Red Hat Enterprise Linux OpenOffice packages are prone to a local privilege-escalation vulnerability because they were built with insecure library search paths.
Exploiting this issue allows local attackers to execute arbitrary code with the privileges of the user running the affected application.
OpenOffice 1.1.x built and shipped with Red Hat Enterprise Linux 3 and 4 are affected.
Exploit / POC
Red Hat Enterprise Linux OpenOffice Insecure Library Path Local Privilege Escalation Vulnerability
An attacker can exploit this issue by gaining local interactive access to the affected computer.
An attacker can exploit this issue by gaining local interactive access to the affected computer.
Solution / Fix
Red Hat Enterprise Linux OpenOffice Insecure Library Path Local Privilege Escalation Vulnerability
Solution:
Please see the referenced advisory for information on obtaining and applying the appropriate updates.
Solution:
Please see the referenced advisory for information on obtaining and applying the appropriate updates.
References
Red Hat Enterprise Linux OpenOffice Insecure Library Path Local Privilege Escalation Vulnerability
References:
References: