After nearly two years since the last update, a corrective release of the Apache OpenOffice 4.1.16 office suite has been published, addressing 7 vulnerabilities and fixing several bugs. Packages have been prepared for Linux, Windows, and macOS.
Resolved vulnerabilities:
- CVE-2025-64406 — buffer overflow when importing specially crafted files in CSV format. This vulnerability may potentially lead to data overwriting in memory and arbitrary code execution in the system.
- CVE-2025-64407 — the URL loading function could be exploited to transfer server environment variables and values from INI files when opening a document with specially crafted external links that load without the user's knowledge. Among the arguments of such links, various settings and environment variables could be transmitted.
- CVE-2025-64401, CVE-2025-64402, CVE-2025-64403, CVE-2025-64404, CVE-2025-64405 — the possibility of loading external content into a document without user operation confirmation through iframe manipulation, OLE objects, external data sources in Calc, DDE functions, and background images. The issues were caused by the ability to substitute external links in the document, the content of which is loaded without user notification.
Among the non-security-related changes:
- Support for document encryption in ODF 1.2 format has been implemented using the AES-256 algorithm.
- Compatibility with the MathML specification has been improved.
- The unused module 'bmpmaker' has been removed.
- On the macOS platform, automatic update checking that led to mutual blocking has been disabled.
- 18 issues have been fixed, including a hang during the update check, the scaling slider disappearing when changing pages in Draw/Impress, incorrect parsing of certain CSV files, crashes upon startup with certain fonts, and improper clearing of the recently opened documents list.
Source: opennet.ru
