Symlink Follow Vulnerability in StarOffice by Sun Microsystems
CVE-2000-1156

Currently unrated

Key Information:

Vendor

Oracle

Vendor
CVE Published:
9 January 2001

What is CVE-2000-1156?

The StarOffice 5.2 suite developed by Sun Microsystems has a vulnerability that allows local users to read other users' files. This is due to its handling of symbolic links in the /tmp/soffice.tmp directory, where it grants world-readable permissions. Anyone with local access can exploit this flaw to gain unauthorized access to sensitive information from other users who are currently utilizing the StarOffice application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.