PT-2021-3326 · Apache · Apache Openoffice+1
Fabian Bräunlein
+1
·
Published
2021-04-15
·
Updated
2021-04-23
·
CVE-2021-30245
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache OpenOffice versions prior to 4.1.10
Description
The issue is related to the handling of non-http(s) hyperlinks in Apache OpenOffice, which can lead to untrusted code execution if a link is specifically crafted. This problem has existed since about 2006. It is recommended to be careful when opening documents from unknown and unverified sources.
Recommendations
For versions prior to 4.1.10, consider avoiding the use of non-http(s) hyperlinks in documents until a patch is available. As a temporary workaround, users should exercise caution when opening documents from unknown sources and avoid clicking on suspicious links. In the upcoming version 4.1.10, a security warning will be displayed when opening potentially dangerous hyperlinks, giving the user the option to continue or cancel the action.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Openoffice
Openoffice