oss-sec mailing list archives

CVE-2012-5639: Apache OpenOffice: Loading internal / external resources without warning


From: Arrigo Marchiori <ardovm () apache org>
Date: Thu, 28 Dec 2023 22:08:02 +0100

Severity: Moderate

Affected versions:

- Apache OpenOffice through 4.1.15

Description:

In Apache OpenOffice and LibreOffice embedded content will be opened
automatically without that a warning is shown.

Credit:

The Apache OpenOffice Security Team would like to thank Timo Warns and
Joachim Mammele for discovering and reporting this attack vector.

References:
https://openoffice.apache.org/
https://www.cve.org/CVERecord?id=CVE-2012-5639
-- 
Arrigo


Current thread: