Re: Richiesta urgente

2021-09-01 Thread Arrigo Marchiori
English version follows. Buongiorno Valentina, in questa lista si scrive in Inglese; per questo non hai ancora ricevuto risposte. Non dovrebbe essere necessario alcun abbonamento per utilizzare OpenOffice. Potresti aver scaricato un programma sbagliato. Ti suggerisco di disinstallarlo e ri-scari

CVE-2022-38745: Apache OpenOffice: Empty entry in Java class path

2023-03-24 Thread Arrigo Marchiori
Severity: moderate Description: Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory. Credit: European Commission's Open Source Programme Office (sponsor) References: http

Re: Saving of a document malfunctional

2023-04-01 Thread Arrigo Marchiori
Hello, On Sat, Apr 01, 2023 at 02:48:32AM +0200, Matej Varga wrote: > Good morning > > I have had a problem with Apache OpenOffice v. 4.1.7. - a text document was > not saved after the first saving, only after the second one and more > consecutive savings. > Therefore, I have downloaded and inst

Re: Saving of a document malfunctional

2023-04-05 Thread Arrigo Marchiori
the file. If you copy and paste all of it, or parts of it, into anoter file, does this other file show the same behavior? If so, you could share the least possible part that triggers the problem. I hope this helps. Best regards. > so 1. 4. 2023 o 20:24 Arrigo Marchiori napĂ­sal(a): > >

CVE-2023-47804: Apache OpenOffice: Macro URL arbitrary script execution

2023-12-28 Thread Arrigo Marchiori
Severity: important Affected versions: - Apache OpenOffice through 4.1.15 Description: Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document

CVE-2023-47804: Apache OpenOffice: Macro URL arbitrary script execution

2023-12-28 Thread Arrigo Marchiori
Severity: important Affected versions: - Apache OpenOffice through 4.1.15 Description: Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document

CVE-2023-1183: Apache OpenOffice: Arbitrary file write in Apache OpenOffice Base

2023-12-28 Thread Arrigo Marchiori
Severity: Moderate Affected versions: - Apache OpenOffice through 4.1.15 Description: An attacker can craft an OBD containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker. There are no

CVE-2022-43680: Apache OpenOffice: "Use after free" fixed in libexpat

2023-12-28 Thread Arrigo Marchiori
Severity: Moderate Affected versions: - Apache OpenOffice through 4.1.15 Description: In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. References: https://openoffice.apache.org/ h

CVE-2012-5639: Apache OpenOffice: Loading internal / external resources without warning

2023-12-28 Thread Arrigo Marchiori
Severity: Moderate Affected versions: - Apache OpenOffice through 4.1.15 Description: In Apache OpenOffice and LibreOffice embedded content will be opened automatically without that a warning is shown. Credit: The Apache OpenOffice Security Team would like to thank Timo Warns and Joachim Mamm

Back to the Future Initiative

2024-03-31 Thread Arrigo Marchiori
Dear All, The Apache OpenOffice Development Team is proud to announce that the next releases will introduce an important change: a text-only user interface. Read more: https://openoffice.apache.org/blog/back-to-the-future-initiative.html :-) -- Arrigo --