Release Date: | 2011-01-28 |
Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a .. (dot dot) in an entry in (1) an XSLT JAR filter description file, (2) an Extension (aka OXT) file, or unspecified other (3) JAR or (4) ZIP files.
See more information about CVE-2010-3450 from MITRE CVE dictionary and NIST NVD
NOTE: The following CVSS v2.0 metrics and score provided are preliminary and subject to review.
Base Score: | 9.3 | Base Metrics: | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Access Vector: | Network | Attack Complexity: | Medium |
Authentication: | None required | Confidentiality Impact: | Complete |
Integrity Impact: | Complete | Availability Impact: | Complete |
Platform | Errata | Release Date |
Oracle Enterprise Linux version 4 (openoffice.org) | ELSA-2011-0181 | 2011-01-28 |
Oracle Linux version 6 (openoffice.org) | ELSA-2011-0183 | 2011-02-10 |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team