Re: HeliSec: StarOffice symlink exploit

2001-02-22 Thread JeT Li
I reported this problem to BUGTRAQ on November 8, 2000. See http://www.securityfocus.com/bid/1922 for more details. I believe Sun has now released patches for this issue. It always helps to do a search before reporting a "new" vulnerability. :-) Regards, Christian. Hi

Re: HeliSec: StarOffice symlink exploit

2001-02-22 Thread Kurt Seifried
StarOffice creates a temporary directory in /tmp called soffice.tmp, with permissions 0777. Into this directory other temporary files are creates, with the format: sv.tmp, where in a four or five digits number. Staroffice honors $TMP, so create /home/foo/tmp and set your TMP

Re: HeliSec: StarOffice symlink exploit

2001-02-20 Thread Peter W
On Sat, Feb 17, 2001 at 04:57:23PM +0100, JeT Li wrote: One way to fix the problem is to create a directory inside your home directory which is inaccessible to anyone but yourself (permissions 700), called tmp. Then insert an entry in your login start-up file to set the $TMP

HeliSec: StarOffice symlink exploit

2001-02-19 Thread JeT Li
- = Helios Security and Administration = - Hi everyone, StarOffice creates a temporary directory in /tmp called soffice.tmp, with permissions 0777. Into this directory other temporary files are creates, with the format: sv.tmp, where in a four or five digits