CVE-2008-2366
openoffice.org: insecure relative RPATH in OOo 1.1.x packages
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Untrusted search path vulnerability in a certain Red Hat build script for OpenOffice.org (OOo) 1.1.x on Red Hat Enterprise Linux (RHEL) 3 and 4 allows local users to gain privileges via a malicious library in the current working directory, related to incorrect quoting of the ORIGIN symbol for use in the RPATH library path.
Vulnerabilidad de búsqueda de ruta no confiable en ciertas secuencias de comandos web usadas para "construir" OpenOffice.org (OOo) 1.1.x sobre Red Hat Enterprise Linux (RHEL) 3 y 4, permite a usuarios locales elevar sus privilegios a través de una biblioteca maliciosa en el directorio actual de trabajo en relación a un entrecomillado incorrecto del símbolo ORIGIN para su uso en la ruta de la biblioteca RPATH.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-05-21 CVE Reserved
- 2008-06-16 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-16: Configuration
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://securitytracker.com/id?1020278 | Vdb Entry | |
http://www.securityfocus.com/bid/29695 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43322 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11361 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/30633 | 2017-09-29 | |
http://www.redhat.com/support/errata/RHSA-2008-0538.html | 2017-09-29 | |
https://bugzilla.redhat.com/show_bug.cgi?id=450532 | 2008-06-13 | |
https://access.redhat.com/security/cve/CVE-2008-2366 | 2008-06-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openoffice Search vendor "Openoffice" | Openoffice Search vendor "Openoffice" for product "Openoffice" | 1.1 Search vendor "Openoffice" for product "Openoffice" and version "1.1" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | - |
Safe
|
Openoffice Search vendor "Openoffice" | Openoffice Search vendor "Openoffice" for product "Openoffice" | 1.1 Search vendor "Openoffice" for product "Openoffice" and version "1.1" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 4.0 Search vendor "Redhat" for product "Enterprise Linux" and version "4.0" | - |
Safe
|