Apache OpenOffice users should upgrade to newest security release!
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-28129 +1 in the same advisory: …40439 | While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could allow a crafted attack on files owned by that user or group if they exist. Users who installed the Apache OpenOffice 4.1.8 DEB packaging should upgrade to the latest version of Apache OpenOffice. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2021-33035 | Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data the size of certain fields is not checked: the data is just copied into local variables. A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by altering the contents of the program stack. This issue affects Apache OpenOffice up to and including version 4.1.10 NVD description · AI analysis pending | 7.8 | 51% |
| — | ||
| CVE-2021-41830 | It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25633 for the LibreOffice advisory. NVD description · AI analysis pending | 7.5 group max | 1% |
| — |
Full article304 words · extracted from helpnetsecurity.com · click to collapse
The Apache Software Foundation (ASF) has released Apache OpenOffice 4.1.11, which fixes a handful of security vulnerabilities, including CVE-2021-33035, a recently revealed RCE vulnerability that could be triggered via a specially crafted document.

About Apache OpenOffice
Apache OpenOffice is an open-source office productivity suite that includes a word processor (Writer), a spreadsheet tool (Calc), a presentation editor (Impress), a vector graphics drawing editor (Draw), a mathematical formula editor (Math), and a database management program (Base).
It is developed by the Apache Software Foundation and welcomes contributions from its code community. According to the ASF, since its initial release it has been downloaded by hundreds of millions of users: individuals as well as businesses and organizations.
The suite is available for Windows, macOS and Linux.
The fixed vulnerabilities
As previously mentioned, the fix for CVE-2021-33035 has finally found its way into an official release of the suite.
Apache OpenOffice 4.1.11 also comes with a fix for CVE-2021-40439, a security vulnerability in the third-party XML parser library included in the suite that allowed billion laughs (DoS) attacks.
CVE-2021-41830 and CVE-2021-41832 allow attackers to manipulate signed documents and macros to appear to come from a trusted source, and CVE-2021-41831 allows the manipulation of the timestamp of signed documents. These vulnerabilities were uncovered by researchers Simon Rohlmann, Vladislav Mladenov, Christian Mainka, and Jorg Schwenk of Ruhr University Bochum, Germany, and also affect LibreOffice (they have been fixed in LibreOffice 7.0.6/7.1.2).
Finally, Apache has fixed CVE-2021-28129, a potential security issue with the suite’s DEB package.
For information about other bugs fixed and enhancements/features introduced in Apache OpenOffice 4.1.11, check out the release notes.
“All users of Apache OpenOffice 4.1.10 or earlier are strongly advised to upgrade,” the ASF noted. “Windows 11 users can now also get Apache OpenOffice for selected languages in the Microsoft Store.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/10/12/apache-openoffice-security/