CVE-2000-0175: Buffer Overflow
Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Sun StarOffice StarSchedulerfrom your environment.Uninstall the StarScheduler component (or Sun StarOffice if the component cannot be isolated) if it is not required.
- Configuration
Stop and disable the StarScheduler web server service on affected hosts to prevent remote exploitation via long GET requests.
Sun StarOffice StarScheduler web server enabled = false - Compensating control
Restrict network access to the StarScheduler web server at the perimeter (block access or allow only trusted IPs via firewall/ACL) to prevent remote GET-based attacks.
- Operational
Assume possible root compromise where the service was exposed: audit logs and system integrity, rotate credentials and keys, and rebuild or restore affected systems from known-good backups if compromise is suspected.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0175?
CVE-2000-0175 is considered high severity due to the potential for remote attackers to gain root access.
How do I fix CVE-2000-0175?
To fix CVE-2000-0175, upgrade to a patched version of StarOffice that addresses the buffer overflow vulnerability.
What software is affected by CVE-2000-0175?
CVE-2000-0175 affects StarOffice version 5.1.
What type of vulnerability is CVE-2000-0175?
CVE-2000-0175 is a buffer overflow vulnerability in the StarScheduler web server.
Can CVE-2000-0175 be exploited remotely?
Yes, CVE-2000-0175 can be exploited remotely via a long GET command.