CVE Database
/

CVE-2021-28129

Back to search

CVE-2021-28129

Published: Oct 7, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could allow a crafted attack on files owned by that user or group if they exist. Users who installed the Apache OpenOffice 4.1.8 DEB packaging should upgrade to the latest version of Apache OpenOffice.

VendorProductVersions

Apache Software Foundation

Apache OpenOffice

affected
Apache OpenOffice 4.1.8

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now