A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Openoffice | — | Upgrade Apache OpenOffice to the latest version | Sep 12, 2025 | Nov 20, 2017 |
| Debian | — | Upgrade libreoffice | Nov 10, 2017 | Sep 11, 2016 |
| Freebsd | — | Upgrade apache-openoffice-develUpgrade apache-openoffice | Oct 27, 2017 | Oct 24, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 26, 2017 |
| Ubuntu | — | Upgrade libreoffice-core | Nov 2, 2017 | Sep 11, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub