[Full-disclosure] fun of openoffice
j.schipper at math.uu.nl
Sat Feb 25 15:39:05 GMT 2006
On Sat, Feb 25, 2006 at 11:29:28PM +0800, alert7 at xfocus.org wrote:
> find a fun of openoffice 1.9.104
> [alert7 at FC4 ~]$ touch ..\\..\\..\\etc\\passwd
> [alert7 at FC4 ~]$ cat ..\\..\\..\\etc\\passwd
> [alert7 at FC4 ~]$ ooffice ..\\..\\..\\etc\\passwd
> /etc/passwd will be open.
> fun bug :)
If you want to call it a bug at all, it should be reported to the OO.o
developers. It's not like it can be used for anything interesting at
all, can it? And I don't see how it is a problem, either.
Full-Disclosure is hosted and sponsored by Secunia.