CVE-2021-30245: Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks

2021-04-15 Thread Dave Fisher
Severity: moderate Description: The project received a report that all versions of Apache OpenOffice through 4.1.8 can open non-http(s) hyperlinks. The problem has existed since about 2006 and the issue is also in 4.1.9. If the link is specifically crafted this could lead to untrusted code exe

Re: CVE-2021-30245: Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks

2021-04-15 Thread Dave Fisher
Hi - We are working on releasing 4.1.10 soon do to this security report [1] which was announced today. I’d like to credit Arrigo Marchiori and Carl Marcum for development. Ariel Constenla-Haile and Peter Kovacs for our indispensible OpenGrok setup. Matthias Seidel, Marcus Lange, Jim Jagielski,

Re: CVE-2021-30245: Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks

2021-04-15 Thread Ilgar Garayev
Thans Dave, for your letter. ilgarexampl...@gmail.com пт, 16 Апр 2021, 3:57 Dave Fisher : > Severity: moderate > > Description: > > The project received a report that all versions of Apache OpenOffice > through 4.1.8 can open non-http(s) hyperlinks. The problem has existed > since about 2006 and