CVE-2021-41832 – Content Manipulation with Certificate Validation Attack
https://notcve.org/view.php?id=CVE-2021-41832
It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25635 for the LibreOffice advisory. Es posible que un atacante manipule los documentos para que parezcan estar firmados por una fuente confiable. • https://lists.apache.org/thread.html/rd3214a568b43dd335b5d558f521377f4bff750684dea18eb041fc1bb%40%3Cusers.openoffice.apache.org%3E https://lists.apache.org/thread.html/rfbc93cd7cea40e2ad3b6e080f688dd02566cdd2b1984fcbb6f8b0fb6%40%3Cannounce.apache.org%3E • CWE-347: Improper Verification of Cryptographic Signature •
CVE-2021-41831 – Timestamp Manipulation with Signature Wrapping
https://notcve.org/view.php?id=CVE-2021-41831
It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25634 for the LibreOffice advisory. Es posible que un atacante manipule la marca de tiempo de los documentos firmados. • https://lists.apache.org/thread.html/ra74d5057cdc781a36286a83e8bcbc90a7678f030ae73339c35dfc4f9%40%3Cusers.openoffice.apache.org%3E https://lists.apache.org/thread.html/rc5c277cb83e335696657c5f27da1d1e2b5cb48346b0b55415a233757%40%3Cannounce.apache.org%3E • CWE-347: Improper Verification of Cryptographic Signature •
CVE-2021-41830 – Double Certificate Attack
https://notcve.org/view.php?id=CVE-2021-41830
It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25633 for the LibreOffice advisory. Es posible que un atacante manipule documentos y macros firmados para que parezcan proceder de una fuente confiable. • https://lists.apache.org/thread.html/r97d287c88881aa581f1b18cb01e2cbedc4e6eae85958491acb89b12e%40%3Cusers.openoffice.apache.org%3E https://lists.apache.org/thread.html/raaab8a3b91f8d7b7ba14f873b8d0fd13952c823acc3385b7a374e754%40%3Cannounce.apache.org%3E • CWE-347: Improper Verification of Cryptographic Signature •
CVE-2021-40439 – Billion Laughs
https://notcve.org/view.php?id=CVE-2021-40439
Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denial of service attack and exploit via crafted XML files. ODF files consist of a set of XML files. All versions of Apache OpenOffice up to 4.1.10 are subject to this issue. expat in version 4.1.11 is patched. Apache OpenOffice presenta una dependencia del software expat. • http://www.openwall.com/lists/oss-security/2021/10/07/4 https://lists.apache.org/thread.html/r41eca5f4f09e74436cbb05dec450fc2bef37b5d3e966aa7cc5fada6d%40%3Cannounce.apache.org%3E https://lists.apache.org/thread.html/rfb2c193360436e230b85547e85a41bea0916916f96c501f5b6fc4702%40%3Cusers.openoffice.apache.org%3E • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2021-28129 – DEB packaging for Apache OpenOffice 4.1.8 installed with a non-root userid and groupid
https://notcve.org/view.php?id=CVE-2021-28129
While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could allow a crafted attack on files owned by that user or group if they exist. Users who installed the Apache OpenOffice 4.1.8 DEB packaging should upgrade to the latest version of Apache OpenOffice. Mientras trabajaba en Apache OpenOffice versión 4.1.8, un desarrollador ha detectado que el paquete DEB no se instalaba usando root, sino que usaba un userid y groupid de 500. Ambos causaban problemas con la integración en el escritorio y podía permitir un ataque diseñado en los archivos propiedad de ese usuario o grupo si existían. • http://www.openwall.com/lists/oss-security/2021/10/07/5 https://lists.apache.org/thread.html/r9e72234dd662280fa1a3cca6164d3470a1dbc0d8e53e48ba27f787ce%40%3Cannounce.apache.org%3E https://lists.apache.org/thread.html/rc9090ab48b4699494b63b35cd6d7414c52d665ecae12add3cdc56c9b%40%3Cusers.openoffice.apache.org%3E • CWE-284: Improper Access Control •