1. Join Date : Aug 2014
    Forever West
    Posts : 2,350
    Win10 Home and Pro, Win7 Home, Linux Mint
       18 Oct 2016 #1

    OpenOffice Security message


    Received this E-Mail today:
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA256



    CVE-2016-6804
    <http://cve.mitre.org/cgi-bin/cvename.cgi?name=2016-6804>
    Apache OpenOffice Advisory
    <https://www.openoffice.org/security/...2016-6804.html>

    Title: Windows Installer Execution of Arbitrary Code with Elevated Privileges

    Version 1.0
    Announced October 11, 2016

    Description

    The Apache OpenOffice installer for Windows contained a defective
    operation that allows execution of arbitrary code with elevated
    privileges.

    The location in which the installer is run may have been previously
    poisoned by a file that impersonates a dynamio-link library that
    the installer depends upon. The counterfeit is operated instead
    because of a search-path defect in the installer. The counterfeit
    will be operated under the administrative privileges of the OpenOffice
    installer, compromising the user's PC.

    Severity: Medium

    There are no known exploits of this vulnerability.
    Proof-of-concept demonstrations exist.

    Vendor: The Apache Software Foundation

    Versions Affected:

    All Apache OpenOffice versions 4.1.2 and older
    are affected. OpenOffice.org versions are also
    affected.


    Mitigation:

    Install Apache OpenOffice 4.1.3 for the latest maintenance and
    cumulative security fixes. Use <https://www.openoffice.org/download/>.


    Defenses and Work-Arounds:

    If you are unable to update to 4.1.3, there are other
    precautions that can be taken. These precautions are also
    recommended as protection against other software that may
    have the vulnerability.

    When executing .exe installers, ensure that the installer
    is in a file folder that has no files but the installer
    .exe file.

    If an installer proposes a folder to extract the setup
    files into before the actual install, choose the name of
    a folder that is not in use. Delete such a folder of setup
    files after the installation completes successfully. To
    reinstall without downloading again, preserve the installer
    .exe on private removable storage.


    Further Information:

    For additional information and assistance, consult the Apache
    OpenOffice Community Forums, <https://forum.openoffice.org/> or
    make requests to the <mailto:users@openoffice.apache.org> public
    mailing list. Defects not involving suspected security
    vulnerabilities can be reported via
    <http://www.openoffice.org/qa/issue_h...ubmission.html>.


    The latest information on Apache OpenOffice security bulletins
    can be found at the Bulletin Archive page
    <http://www.openoffice.org/security/bulletin.html>.

    Credits:

    The Apache OpenOffice project acknowledges the reporting and
    analysis for CVE-2016-6804 by Stefan Kanthak and by Himanshu Mehta.

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v2

    iQEcBAEBCAAGBQJYBkKGAAoJEPluif/UVmKKH/0H/2KV5JJC2lTjxMfxfxRchyr9
    aT32OzSJQRh6cAH8OZ44ucapUMmGZBaSQDwgqFTh94txlVEzeavUlCTmxFgBqdzt
    TIEiEnPWfNlA6wgHX7JDcq1UGnwCpFjY9Vko5dFRrJLiBU+QP6AcN5DLQGeYF2rU
    xpDOzQWLbSFIWZ0ASzuLC42iP0minJVaD9E0kK+D0vWLTd5v8PM7az/wQY2n4Znn
    89SMdXD1zsBED5RfT0wIBDnN6RrllzebcvXRgSxS1Q9w7FvHBUvVijv1LYNVtd9u
    rmUc2v3+1IC73xXrwLBxJxZEFJY4bxtJv3NCoyzg0gH1Ooz9z+qyTXBPp4gyMZA=
    =DB7A
    -----END PGP SIGNATURE-----
      My System SpecsSystem Spec

  2.    18 Oct 2016 #2

    I believe they have stopped developing OpenOffice now. You should switch to LibreOffice which is a fork of the original OpenOffice and better IMO.
      My System SpecsSystem Spec


  3. Join Date : Aug 2014
    Forever West
    Posts : 2,350
    Win10 Home and Pro, Win7 Home, Linux Mint
       18 Oct 2016 #3

    swarfega said: View Post
    I believe they have stopped developing OpenOffice now. You should switch to LibreOffice which is a fork of the original OpenOffice and better IMO.
    Agreed, been using LibreOffice for several years now.
      My System SpecsSystem Spec


 


Similar Threads
Thread Forum
Openoffice will not start
Just got a new HP desktop and I can't get MS Office 2003 to set-up in Win10 . It ran great on Win7 and Winxp over a number of years. I'm sure the 25 character code is correct and I have the start-up disk in the drive . Any reason why it stopped...
Software and Apps
Solved Turn on windows security center service nagging message
32817 Every time I switch on my PC, after about 5 minutes, I get this annoying notification (see picture) from my OS asking me to turn on the security center service; please, note that, on my PC, I am judge, jury and executioner, meaning I decide...
AntiVirus, Firewalls and System Security
Default printer in OpenOffice
Hi, We're having a problem with setting a default printer in OO. Every time we select a printer; after the program is shutdown and starts up again it reverts to the XPS Writer as default. I've already unchecked the box that loads the printer...
Software and Apps
Reboot error message "kernel security check failure"
Please help. When my Toshiba Satellite L655 laptop was rebooted I got the above error. This laptop was upgraded from Win 7 to Win 10 about a month ago. I don't know if this is related or not but two days prior to this error today, the battery...
BSOD Crashes and Debugging
Using OpenOffice
I've been using MSWord for years. I am now using OpenOffice Writer. With the dozens of files I made with Word which have a file extension of DOC or DOCX. If I click on one of those files it will open MSWord but I want them to open OpenOffice Writer...
Software and Apps
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd

All times are GMT -5. The time now is 01:02.
Find Us
Twitter Facebook Google+



Windows 10 Forums