QID 379284

Date Published: 2024-01-31

QID 379284: Apache OpenOffice Multiple Security Vulnerabilities

Apache OpenOffice (AOO) is an open-source office productivity software suite.

CVE-2012-5639: Loading internal / external resource without warning.
CVE-2022-43680: "Use after free" fixed in expat >= 2.4.9.
CVE-2023-1183: Arbitrary file write in Base.
CVE-2023-47804: Macro URL arbitrary script execution.

Affected Versions:
All Apache OpenOffice versions 4.1.14 and older are affected

QID Detection Logic (Authenticated):
This QID checks the vulnerable version of OpenOffice by checking the file version of file "soffice.exe".

In the affected versions of OpenOffice, approval for certain links is not requested; when activated, such links could therefore result in arbitrary script execution.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Users are advised to upgrade to Apache OpenOffice 4.1.15 of the software available.Latest version of the software can be downloaded from LibreOffice
    Software Advisories
    Advisory ID Software Component Link
    Apache OpenOffice URL Logo www.openoffice.org/security/cves/CVE-2023-47804.html