CVE-2022-38745

NameCVE-2022-38745
DescriptionApache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3526-1, ELA-968-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libreoffice (PTS)jessie, jessie (lts)1:4.3.3-2+deb8u15vulnerable
stretch (security)1:5.2.7-1+deb9u11vulnerable
stretch (lts), stretch1:6.1.5-3+deb9u5fixed
buster, buster (lts)1:6.1.5-3+deb10u14fixed
buster (security)1:6.1.5-3+deb10u12fixed
bullseye1:7.0.4-4+deb11u10fixed
bullseye (security)1:7.0.4-4+deb11u11fixed
bookworm (security), bookworm4:7.4.7-1+deb12u5fixed
trixie4:24.8.3-3fixed
sid4:24.8.4-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libreofficesourcestretch1:6.1.5-3~deb9u1ELA-968-1
libreofficesourcebuster1:6.1.5-3+deb10u10DLA-3526-1
libreofficesourcebullseye1:7.0.4-4+deb11u6
libreofficesource(unstable)1:7.3.1-1

Notes

https://cgit.freedesktop.org/libreoffice/core/commit/?id=5e8f64e50f97d39e83a3358697be14db03566878
https://www.libreoffice.org/about-us/security/advisories/CVE-2022-38745
[jessie] - libreoffice <ignored> (GUI/non-headless not supported, too risky to backport, massive internal library changes, attack vector is rather local)

Search for package or bug name: Reporting problems