On 10/2/26 13:30, Dave Fisher wrote: > Severity: critical > > Affected versions: > > - Apache OpenOffice through 4.1.16 > - Apache OpenOffice before 95923fd437e06edd38a4f0e139a27c755a6f3ba6 > - Apache OpenOffice before 181421139242694b309751fb666406eddc203c50 > > Description: > > A code execution issue in the Java integration in Apache OpenOffice v4.1.16 > and earlier allows a crafted untrusted document to trigger executing > arbitrary (even remote) code when opened by the user. > > > > This issue is expected to be fixed in version 4.1.17, which is in the release > candidate phase. > > > > Until then, users can mitigate this issue by disabling Java runtime > integration in the Preferences dialog. This prevents the attack. If this is > not possible, or as an extra precaution, you can avoid opening open untrusted > files entirely. Once 4.1.17 is released, upgrade to that version to fix the > issue. > > Credit: > > Thomas Rinsma and Edoardo Geraci from Codean Labs (finder) > Rick de Jager (finder) > > References: > > https://github.com/apache/openoffice/commit/c699bed3f75e79bd64ddec9dec49f9e210eed281.patch > https://github.com/apache/openoffice/commit/95923fd437e06edd38a4f0e139a27c755a6f3ba6.patch > https://openoffice.apache.org/ > https://www.cve.org/CVERecord?id=CVE-2026-59265
Does this apply to LibreOffice? -- Sincerely, Demi Marie Obenour (she/her/hers)
OpenPGP_signature.asc
Description: OpenPGP digital signature
