content/security/cves/CVE-2022-38745.html (84 lines of code) (raw):

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /> <title>CVE-2022-38745</title> </head> <body> <p> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-38745">CVE-2022-38745</a> </p> <p> <a href="https://www.openoffice.org/security/cves/CVE-2022-38745.html">Apache OpenOffice Advisory</a> </p> <p style="text-align:center; font-size:largest"> <strong>An empty class path may lead to run arbitrary Java code</strong> </p> <p style="text-align:center; font-size:larger"> <strong>Fixed in Apache OpenOffice 4.1.14</strong> </p> <p> <strong>Description</strong> </p> <p> Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory. </p> <p> <strong>Severity: Moderate</strong> </p> <p> There are no known exploits of this vulnerability. <br /> A proof-of-concept demonstration does not exist. </p> <p> Thanks to the reporter for discovering this issue. </p> <p> <strong>Vendor: The Apache Software Foundation</strong> </p> <p> <strong>Versions Affected</strong> </p> <p> All Apache OpenOffice versions 4.1.13 and older are affected. <br /> OpenOffice.org versions may also be affected. </p> <p> <strong>Mitigation</strong> </p> <p> Install Apache OpenOffice 4.1.14 for the latest maintenance and cumulative security fixes. Use the Apache OpenOffice <a href="https://www.openoffice.org/download/"> download page</a>. </p> <p> <strong>Acknowledgments</strong> </p> <p> The Apache OpenOffice Security Team would like to thank the European Commission's Open Source Programme Office for discovering and reporting this attack vector. </p> <p> <strong>Further Information</strong> </p> <p> For additional information and assistance, consult the <a href="https://forum.openoffice.org/">Apache OpenOffice Community Forums</a> or make requests to the <a href="mailto:users@openoffice.apache.org">users@openoffice.apache.org</a> public mailing list. </p> <p> The latest information on Apache OpenOffice security bulletins can be found at the <a href="https://www.openoffice.org/security/bulletin.html">Bulletin Archive page</a>. </p> <hr /> <p> <a href="https://security.openoffice.org">Security Home</a>-&gt; <a href="https://www.openoffice.org/security/bulletin.html">Bulletin</a>-&gt; <a href="https://www.openoffice.org/security/cves/CVE-2022-38745.html">CVE-2022-38745</a> </p> </body> </html>