Release of Apache OpenOffice 4.1.10 addressing vulnerabilities also affecting LibreOffice.

After three months of development and seven years since the last major release, a corrective release of the Apache OpenOffice 4.1.10 office suite has been prepared, offering 2 fixes. Packages are available for Linux, Windows, and macOS.

The release addresses a vulnerability (CVE-2021-30245) that allows arbitrary code execution in the system when clicking on a specially crafted link in a document. This vulnerability arises from a flaw in handling hyperlinks that use protocols other than "http://" and "https://", such as "smb://" and "dav://".

For instance, an attacker might host an executable on their SMB server and insert a link to it in a document. When a user clicks on this link, the specified executable will run without warning. The possibility of such an attack has been demonstrated on Windows and Xubuntu. To safeguard against this in OpenOffice 4.1.10, an additional dialog has been added that requires user confirmation when following a link in a document.

Researchers who identified the issue noted that it affects not only Apache OpenOffice but also LibreOffice (CVE-2021-25631). For LibreOffice, a fix is currently available as a patch included in the releases of LibreOffice 7.0.5 and 7.1.2, but it only resolves the problem on the Windows platform (the list of prohibited file extensions has been updated). The LibreOffice developers declined to include a fix for Linux, stating that the problem lies outside their responsibility and should be addressed by distributions/user environments. Similar issues have also been identified in Telegram, Nextcloud, VLC, Bitcoin/Dogecoin Wallet, Wireshark, and Mumble.



Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster