Apache openoffice latest version10/14/2023 Why: The mitigation in Apache OpenOffice 4.1.10 assures that a security warning is displayed to give users the option of continuing to open the hyperlink. How: Applications of the OpenOffice suite handle non-http(s) hyperlinks in an insecure way, allowing for 1-click code execution on Windows and Xubuntu systems via malicious executable files hosted on Internet-accessible file shares. >Credit: Fabian Bräunlein and Lukas Euler of Positive Security > CVE-2021-30245: Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks The Apache OpenOffice Project has filed a Common Vulnerabilities and Exposures report with MITRE Corporation’s national vulnerability reporting system: What: A recently reported vulnerability states that all versions of OpenOffice through 4.1.9 can open non-http(s) hyperlinks, and could lead to untrusted code execution. Apache OpenOffice delivers up to 2.4 Million downloads each month. The OpenOffice suite is based around the OpenDocument Format (ODF), supports 41 languages, and ships for Windows, macOS, Linux 64-bit, and Linux 32-bit. Since 2012, AOO is said to have been downloaded 250 million times.Wilmington, DE, (GLOBE NEWSWIRE) - Who: Apache OpenOffice, an Open Source office-document productivity suite comprising six productivity applications: Writer, Calc, Impress, Draw, Math, and Base. LibreOffice earlier this year celebrated 969,108 downloads two weeks after the release of version 6.0.ĭuring the two weeks that followed after the release of AOO 4.1.5, there were 1,487,514 downloads. Four years later, there's been almost no growth: the current list of Apache OpenOffice Committers includes 141 names.Īnd yet AOO has fans, or at least users. Back in 2014, AOO published a graph of code committers, peaking at 140 in August that year. But evidence of volunteer enthusiasm is hard to come by. Were interest surging, as Jagielski suggested, that might not be a problem. Planned enhancements, Kovacs says, depend mainly on volunteer contributions. The AOO devs say they want to do one release a year, apart from necessary security patches. When it will see release is anybody's guess. The developers of AOO want to 4.2.x line to be based on the Windows 10 SDK and a more recent macOS build – the software has been tested with macOS 10.13 (High Sierra). The 4.1.x line is based on the Windows 7 SDK and macOS 10.7 (Lion), both of which are no longer supported.
0 Comments
Leave a Reply.AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |