OpenOffice Installation Insecure Temporary File Symbolic Link Vulnerability
BID:5950
Info
OpenOffice Installation Insecure Temporary File Symbolic Link Vulnerability
| Bugtraq ID: | 5950 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 11 2002 12:00AM |
| Updated: | Oct 11 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Larry W. Cashdollar <[email protected]>. |
| Vulnerable: |
OpenOffice OpenOffice 1.0.1 |
| Not Vulnerable: | |
Discussion
OpenOffice Installation Insecure Temporary File Symbolic Link Vulnerability
OpenOffice is an open source office software package distributed and maintained by the OpenOffice project. It is available for Unix, Linux, and Microsoft Windows operating systems.
A vulnerability in the installation process of OpenOffice has been reported. When OpenOffice is installed, it insecurely creates temporary files. Temporary files created by the office suite are created with a predictable file name. Additionally, a check is not performed prior to the attempted writing to the file. This could result in the destruction of files with the permissions of the user installation OpenOffice if attackers create symbolic links with the correct filename.
OpenOffice is an open source office software package distributed and maintained by the OpenOffice project. It is available for Unix, Linux, and Microsoft Windows operating systems.
A vulnerability in the installation process of OpenOffice has been reported. When OpenOffice is installed, it insecurely creates temporary files. Temporary files created by the office suite are created with a predictable file name. Additionally, a check is not performed prior to the attempted writing to the file. This could result in the destruction of files with the permissions of the user installation OpenOffice if attackers create symbolic links with the correct filename.
Exploit / POC
OpenOffice Installation Insecure Temporary File Symbolic Link Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
OpenOffice Installation Insecure Temporary File Symbolic Link Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
OpenOffice Installation Insecure Temporary File Symbolic Link Vulnerability
References:
References:
- OpenOffice Homepage (OpenOffice)