CVE-2014-5236: Path Traversal
Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5236?
CVE-2014-5236 has a medium severity rating due to its potential to allow unauthorized access to sensitive files.
How do I fix CVE-2014-5236?
To fix CVE-2014-5236, update Open-Xchange AppSuite to version 7.4.2-rev10 or 7.6.0-rev10 or later.
Who is affected by CVE-2014-5236?
CVE-2014-5236 affects versions of Open-Xchange AppSuite up to and including 7.4.1 and several 7.4.2 and 7.6.0 revisions.
What kind of attacks can exploit CVE-2014-5236?
CVE-2014-5236 can be exploited through crafted OpenDocument text files containing OLE Objects or images.
What does CVE-2014-5236 allow attackers to do?
CVE-2014-5236 allows remote attackers to read application files by using absolute path traversal vulnerabilities.