CVE-2008-4937: Low severity apache openoffice vulnerability
Published Nov 5, 2008
·Updated
senddoc in OpenOffice.org (OOo) 2.4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/log.obr.##### temporary file.
Affected Software
1 affected component
OpenOffice OpenOffice.org=2.4.1
Event History
Nov 5, 2008
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4937?
CVE-2008-4937 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2008-4937?
To fix CVE-2008-4937, users should avoid using OpenOffice.org 2.4.1 or implement access controls to the /tmp directory.
3
What type of attack does CVE-2008-4937 represent?
CVE-2008-4937 represents a symlink attack that allows local users to overwrite arbitrary files.
4
Which version of OpenOffice.org is affected by CVE-2008-4937?
Only OpenOffice.org version 2.4.1 is affected by CVE-2008-4937.
5
Can CVE-2008-4937 be exploited remotely?
No, CVE-2008-4937 can only be exploited by local users with access to the file system.