QID 375605
Date Published: 2021-08-03
QID 375605: Apache OpenOffice Untrusted Code Execution Vulnerability
Apache OpenOffice (AOO) is an open-source office productivity software suite.
All versions of Apache OpenOffice through 4.1.8 can open non-http(s) hyperlinks. The problem has existed since about 2006 and the issue is also in 4.1.9.
Affected Versions:
OpenOffice versions 4.1.9 and older are affected
QID Detection Logic (Authenticated):
This QID checks the vulnerable version of OpenOffice by checking the file version of file "soffice.exe".
If the link is specifically crafted this could lead to untrusted code execution.
Solution
Users are advised to upgrade to Apache OpenOffice 4.1.10 of the software available.Latest version of the software can be downloaded from LibreOffice
Vendor References
- Apache OpenOffice -
www.openoffice.org/security/cves/CVE-2021-30245.html
CVEs related to QID 375605
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache OpenOffice |
|