Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
OpenOffice (OOo) 1.1.2 creates predictable directory names with insecure permissions during startup, which may allow local users to read or list files of other users.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenOffice临时文件泄露漏洞
Vulnerability Description
OpenOffice是一款办公处理软件,支持多种操作系统。 OpenOffice建立临时文件目录权限不正确,本地攻击者可以利用这个漏洞获得敏感文件信息。 当运行OpenOffice时,会建立/tmp/sv<RAND>.tmp目录,此随机值是3个随机字符串。此目录权限允许其他用户执行'cd'命令,并列出其内容。 当文件打开时,会在/tmp/sv<RAND>.tmp目录中建立压缩的文件,权限也允许其他用户可读,因此本地系统用户可以通过查看这些文件获得其他用户敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A