CVE-2010-3689
published 2011-01-28CVE-2010-3689: soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a…
PriorityP424medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.65%
47.1th percentile
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | >= 3.0.0 < 3.3.0 | 3.3.0 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_ubuntu9.3CRITICAL
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hmvp-8rpc-gr57: soffice in OpenOffice
ghsa_unreviewed·2022-05-13
CVE-2010-3689 [MEDIUM] CWE-22 GHSA-hmvp-8rpc-gr57: soffice in OpenOffice
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Ubuntu
OpenOffice.org vulnerabilities
vendor_ubuntu·2011-02-02·CVSS 9.3
CVE-2010-2935 [CRITICAL] OpenOffice.org vulnerabilities
Title: OpenOffice.org vulnerabilities
Summary: Multiple vulnerabilities in OpenOffice.org
Charlie Miller discovered several heap overflows in PPT processing. If
a user or automated system were tricked into opening a specially crafted
PPT document, a remote attacker could execute arbitrary code with user
privileges. Ubuntu 10.10 was not affected. (CVE-2010-2935, CVE-2010-2936)
Marc Schoenefeld discovered that directory traversal was not correctly
handled in XSLT, OXT, JAR, or ZIP files. If a user or automated system
were tricked into opening a specially crafted document, a remote attacker
overwrite arbitrary files, possibly leading to arbitrary code execution
with user privileges. (CVE-2010-3450)
Dan Rosenberg discovered multiple heap overflows in RTF and DOC
processing. If a user or au
Red Hat
OpenOffice.org: soffice insecure LD_LIBRARY_PATH setting
vendor_redhat·2011-01-26·CVSS 6.9
CVE-2010-3689 [MEDIUM] OpenOffice.org: soffice insecure LD_LIBRARY_PATH setting
OpenOffice.org: soffice insecure LD_LIBRARY_PATH setting
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Package: openoffice.org (Red Hat Enterprise Linux 4) - Not affected
No detection rules found.
No public exploits indexed.
http://osvdb.org/70716http://secunia.com/advisories/40775http://secunia.com/advisories/42999http://secunia.com/advisories/43065http://secunia.com/advisories/43105http://secunia.com/advisories/60799http://ubuntu.com/usn/usn-1056-1http://www.debian.org/security/2011/dsa-2151http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:027http://www.openoffice.org/security/cves/CVE-2010-3689.htmlhttp://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0182.htmlhttp://www.securityfocus.com/bid/46031http://www.securitytracker.com/id?1025004http://www.vupen.com/english/advisories/2011/0230http://www.vupen.com/english/advisories/2011/0232http://www.vupen.com/english/advisories/2011/0279https://bugzilla.redhat.com/show_bug.cgi?id=641224http://osvdb.org/70716http://secunia.com/advisories/40775http://secunia.com/advisories/42999http://secunia.com/advisories/43065http://secunia.com/advisories/43105http://secunia.com/advisories/60799http://ubuntu.com/usn/usn-1056-1http://www.debian.org/security/2011/dsa-2151http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:027http://www.openoffice.org/security/cves/CVE-2010-3689.htmlhttp://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0182.htmlhttp://www.securityfocus.com/bid/46031http://www.securitytracker.com/id?1025004http://www.vupen.com/english/advisories/2011/0230http://www.vupen.com/english/advisories/2011/0232http://www.vupen.com/english/advisories/2011/0279https://bugzilla.redhat.com/show_bug.cgi?id=641224
2011-01-28
Published