Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file.
Advisories
Source ID Title
EUVD EUVD EUVD-2014-5134 Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T11:41:48.270Z

Reserved: 2014-08-13T00:00:00

Link: CVE-2014-5236

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-01-31T22:15:10.573

Modified: 2024-11-21T02:11:40.067

Link: CVE-2014-5236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.