CVE
- Id
- 2723
- CVE No.
- CVE-2000-1156
- Status
- Candidate
- Description
- StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice.
- Phase
- Modified (20010116-01)
- Votes
- ACCEPT(3) Baker, Cole, Dik | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey
- Comments
- Frech> XF:staroffice-tmp-sym-link(5487) | Christey> Consult Sun on this one. | Dik> Supposedly fixed in Soffice 5.1 Service pack 1