#VU57209 XML Entity Expansion in OpenOffice - CVE-2021-40439
Published: October 11, 2021
OpenOffice
Apache Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to dependency on an old expat software version. A remote attacker can trick the victim to open a specially crafted ODF file and perform a denial of service (DoS) attack.
The vulnerability in expat is described as #VU42119 (CVE-2013-0340).
Remediation
External links
- https://lists.apache.org/thread.html/rfb2c193360436e230b85547e85a41bea0916916f96c501f5b6fc4702%40%3Cusers.openoffice.apache.org%3E
- https://lists.apache.org/thread.html/r41eca5f4f09e74436cbb05dec450fc2bef37b5d3e966aa7cc5fada6d@%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/rfb2c193360436e230b85547e85a41bea0916916f96c501f5b6fc4702@%3Cusers.openoffice.apache.org%3E
- http://www.openwall.com/lists/oss-security/2021/10/07/4