First published: Tue Dec 31 2002(Updated: )
The installation of OpenOffice 1.0.1 allows local users to overwrite files and possibly gain privileges via a symlink attack on the USERNAME_autoresponse.conf temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenOffice OpenOffice | =1.0.1 | |
Apache OpenOffice | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2210 has a medium severity level due to its potential for privilege escalation through a symlink attack.
To fix CVE-2002-2210, update to a later version of OpenOffice that does not allow the creation of symlinks in the temporary file path.
OpenOffice version 1.0.1 is specifically affected by CVE-2002-2210.
CVE-2002-2210 requires local access to the system, making it not exploitable remotely.
CVE-2002-2210 is a local file overwrite vulnerability resulting from improper handling of temporary files.