CVE-2021-28129
Last modified
CVE-2021-28129 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could allow a crafted attack on files owned by that user or group if they exist. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could allow a crafted attack on files owned by that user or group if they exist. Users who installed the Apache OpenOffice 4.1.8 DEB packaging should upgrade to the latest version of Apache OpenOffice.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Openoffice | 4.1.8 |
References
- http://www.openwall.com/lists/oss-security/2021/10/07/5Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/10/07/5Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-28129?
How severe is CVE-2021-28129?
How do I fix CVE-2021-28129?
Are you affected by CVE-2021-28129?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
