CVE-2000-0174: Medium severity sun staroffice vulnerability
StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Sun StarOffice StarScheduler web serverfrom your environment.Uninstall the StarScheduler web server component from affected systems if it is not required, or stop the service until a patch is available.
- Configuration
Stop and disable the StarScheduler web server/service in StarOffice to prevent remote file-read (.. / dot-dot) attacks until a vendor patch is available.
Sun StarOffice StarScheduler web server service_enabled = false - Compensating control
Restrict network access to the StarScheduler web server to trusted IP addresses or internal networks (e.g., via firewall, ACL, or network segmentation); block external access to the service until a vendor fix is provided.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0174?
CVE-2000-0174 is considered a high severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2000-0174?
To mitigate CVE-2000-0174, update to a patched version of StarOffice or configure the web server to restrict access to sensitive files.
What systems are affected by CVE-2000-0174?
CVE-2000-0174 affects StarOffice version 5.1 specifically.
Can CVE-2000-0174 lead to data breaches?
Yes, CVE-2000-0174 can lead to data breaches as it allows attackers to read arbitrary files on the server.
What type of attack is CVE-2000-0174 associated with?
CVE-2000-0174 is associated with directory traversal attacks, often referred to as dot dot attacks.