[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-disclosure] fun of openoffice
- To: full-disclosure@xxxxxxxxxxxxxxxxx
- Subject: Re: [Full-disclosure] fun of openoffice
- From: Joachim Schipper <j.schipper@xxxxxxxxxx>
- Date: Sat, 25 Feb 2006 16:39:05 +0100
On Sat, Feb 25, 2006 at 11:29:28PM +0800, alert7@xxxxxxxxxx wrote:
> find a fun of openoffice 1.9.104
>
> [alert7@FC4 ~]$ touch ..\\..\\..\\etc\\passwd
> [alert7@FC4 ~]$ cat ..\\..\\..\\etc\\passwd
> [alert7@FC4 ~]$ ooffice ..\\..\\..\\etc\\passwd
> /etc/passwd will be open.
>
> fun bug :)
If you want to call it a bug at all, it should be reported to the OO.o
developers. It's not like it can be used for anything interesting at
all, can it? And I don't see how it is a problem, either.
Joachim
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/