Windows 10: OpenOffice Security message
OpenOffice Security message
Received this E-Mail today:
-----BEGIN PGP SIGNED MESSAGE-----
Apache OpenOffice Advisory
Title: Windows Installer Execution of Arbitrary Code with Elevated Privileges
Announced October 11, 2016
The Apache OpenOffice installer for Windows contained a defective
operation that allows execution of arbitrary code with elevated
The location in which the installer is run may have been previously
poisoned by a file that impersonates a dynamio-link library that
the installer depends upon. The counterfeit is operated instead
because of a search-path defect in the installer. The counterfeit
will be operated under the administrative privileges of the OpenOffice
installer, compromising the user's PC.
There are no known exploits of this vulnerability.
Proof-of-concept demonstrations exist.
Vendor: The Apache Software Foundation
All Apache OpenOffice versions 4.1.2 and older
are affected. OpenOffice.org versions are also
Install Apache OpenOffice 4.1.3 for the latest maintenance and
cumulative security fixes. Use <https://www.openoffice.org/download/>.
Defenses and Work-Arounds:
If you are unable to update to 4.1.3, there are other
precautions that can be taken. These precautions are also
recommended as protection against other software that may
have the vulnerability.
When executing .exe installers, ensure that the installer
is in a file folder that has no files but the installer
If an installer proposes a folder to extract the setup
files into before the actual install, choose the name of
a folder that is not in use. Delete such a folder of setup
files after the installation completes successfully. To
reinstall without downloading again, preserve the installer
.exe on private removable storage.
For additional information and assistance, consult the Apache
OpenOffice Community Forums, <https://forum.openoffice.org/> or
make requests to the <mailto:firstname.lastname@example.org> public
mailing list. Defects not involving suspected security
vulnerabilities can be reported via
The latest information on Apache OpenOffice security bulletins
can be found at the Bulletin Archive page
The Apache OpenOffice project acknowledges the reporting and
analysis for CVE-2016-6804 by Stefan Kanthak and by Himanshu Mehta.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
-----END PGP SIGNATURE-----
I believe they have stopped developing OpenOffice now. You should switch to LibreOffice which is a fork of the original OpenOffice and better IMO.
Agreed, been using LibreOffice for several years now.
Just got a new HP desktop and I can't get MS Office 2003 to set-up in Win10 . It ran great on Win7 and Winxp over a number of years. I'm sure the 25 character code is correct and I have the start-up disk in the drive . Any reason why it stopped...
Every time I switch on my PC, after about 5 minutes, I get this annoying notification (see picture) from my OS asking me to turn on the security center service; please, note that, on my PC, I am judge, jury and executioner, meaning I decide...
We're having a problem with setting a default printer in OO. Every time we select a printer; after the program is shutdown and starts up again it reverts to the XPS Writer as default. I've already unchecked the box that loads the printer...
Please help. When my Toshiba Satellite L655 laptop was rebooted I got the above error. This laptop was upgraded from Win 7 to Win 10 about a month ago. I don't know if this is related or not but two days prior to this error today, the battery...
I've been using MSWord for years. I am now using OpenOffice Writer. With the dozens of files I made with Word which have a file extension of DOC or DOCX. If I click on one of those files it will open MSWord but I want them to open OpenOffice Writer...