QID 379284
Date Published: 2024-01-31
QID 379284: Apache OpenOffice Multiple Security Vulnerabilities
Apache OpenOffice (AOO) is an open-source office productivity software suite.
CVE-2012-5639: Loading internal / external resource without warning.
CVE-2022-43680: "Use after free" fixed in expat >= 2.4.9.
CVE-2023-1183: Arbitrary file write in Base.
CVE-2023-47804: Macro URL arbitrary script execution.
Affected Versions:
All Apache OpenOffice versions 4.1.14 and older are affected
QID Detection Logic (Authenticated):
This QID checks the vulnerable version of OpenOffice by checking the file version of file "soffice.exe".
In the affected versions of OpenOffice, approval for certain links is not requested; when activated, such links could therefore result in arbitrary script execution.
Solution
Users are advised to upgrade to Apache OpenOffice 4.1.15 of the software available.Latest version of the software can be downloaded from LibreOffice
Vendor References
- CVE-2021-28129 -
www.openoffice.org/security/cves/CVE-2021-28129.html - CVE-2021-33035 -
www.openoffice.org/security/cves/CVE-2021-33035.html - CVE-2021-40439 -
www.openoffice.org/security/cves/CVE-2021-40439.html - CVE-2021-41830 -
www.openoffice.org/security/cves/CVE-2021-41830.html - CVE-2021-41831 -
www.openoffice.org/security/cves/CVE-2021-41831.html - CVE-2021-41832 -
www.openoffice.org/security/cves/CVE-2021-41832.html
CVEs related to QID 379284
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache OpenOffice |
|