apache openoffice CVE-2021-28129 is a vulnerability in Apache OpenOffice
Published on October 7, 2021

DEB packaging for Apache OpenOffice 4.1.8 installed with a non-root userid and groupid
While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could allow a crafted attack on files owned by that user or group if they exist. Users who installed the Apache OpenOffice 4.1.8 DEB packaging should upgrade to the latest version of Apache OpenOffice.

NVD

Weakness Type

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2021-28129 has been classified to as an Authorization vulnerability or weakness.


Products Associated with CVE-2021-28129

Want to know whenever a new CVE is published for Apache OpenOffice? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache OpenOffice Version Apache OpenOffice 4.1.8 is affected by CVE-2021-28129

Exploit Probability

EPSS
0.19%
Percentile
40.94%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.