First published: Wed Nov 05 2008(Updated: )
senddoc in OpenOffice.org (OOo) 2.4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/log.obr.##### temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache OpenOffice | =2.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4937 is classified as a moderate severity vulnerability.
To fix CVE-2008-4937, users should avoid using OpenOffice.org 2.4.1 or implement access controls to the /tmp directory.
CVE-2008-4937 represents a symlink attack that allows local users to overwrite arbitrary files.
Only OpenOffice.org version 2.4.1 is affected by CVE-2008-4937.
No, CVE-2008-4937 can only be exploited by local users with access to the file system.