FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Apache OpenOffice -- multiple vulnerabilities.

Affected packages
apache-openoffice < 4.1.11
apache-openoffice-devel < 4.2.1633255994,4

Details

VuXML ID 04d2cf7f-2942-11ec-b48c-1c1b0d9ea7e6
Discovery 2021-05-04
Entry 2021-10-09

The Apache Openoffice project reports:

Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data the size of certain fields is not checked: the data is just copied into local variables. A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by altering the contents of the program stack. This issue affects Apache OpenOffice up to and including version 4.1.10

It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25633 for the LibreOffice advisory

It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25634 for the LibreOffice advisory.

It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25635 for the LibreOffice advisory.

References

CVE Name CVE-2021-33035
CVE Name CVE-2021-41830
CVE Name CVE-2021-41831
CVE Name CVE-2021-41832
URL https://cwiki.apache.org/confluence/display/OOOUSERS/AOO+4.1.11+Release+Notes/#AOO4.1.11ReleaseNotes-Security