Re: Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks

2021-04-16 Thread Jim Jagielski
In prep for 4.1.10 (and our 1st release candidate), we're using https://cwiki.apache.org/confluence/display/OOOUSERS/AOO+4.1.10 for tracking. - To unsubscribe, e-mail: dev-unsubscr...@openoffice.apache.org For additional co

Re: Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks

2021-04-16 Thread Carl Marcum
Thank you Dave for all your work and co-ordination with security, the reporter, and communications. Best regards, Carl On 4/15/21 4:06 PM, Dave Fisher wrote: Hi - Here is some background on the issue which has apparently existed since about OpenOffice.org 2.0 in 2005 or so. See https://bz.a

Re: Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks

2021-04-15 Thread Dave Fisher
Hi - Here is some background on the issue which has apparently existed since about OpenOffice.org 2.0 in 2005 or so. See https://bz.apache.org/ooo/show_bug.cgi?id=49802 Some confusion existed between types of hyperlinks and rather than filtering they were all allowed to proceed. Arrigo restor