28 Jan 2011 12:10
CVE-2010-3689: Insecure LD_LIBRARY_PATH usage in OpenOffice.org shell scripts
Malte Timmermann <malte.timmermann <at> oracle.com>
2011-01-28 11:10:58 GMT
2011-01-28 11:10:58 GMT
CVE-2010-3689
Insecure LD_LIBRARY_PATH usage in OpenOffice.org shell scripts
* Synopsis: The OpenOffice.org start script and other shell scripts
expand the LD_LIBRARY_PATH in a insecure way
* State: Resolved
1. Impact
The OpenOffice.org start script and other shell scripts expand the
LD_LIBRARY_PATH in a way that the current directory might be searched
for libraries before /lib and /usr/lib, which can have security
implications.
2. Affected releases
* All versions of OpenOffice.org 3 prior to version 3.3
Note: OpenOffice.org 2 is not impacted by this issue.
Earlier versions of OpenOffice.org are no longer supported
and will not be evaluated regarding this issue.
3. Symptoms
There are no predictable symptoms that would indicate this issue has
occurred.
4. Relief/Workaround
(Continue reading)
RSS Feed