CVE-2022-38745

NameCVE-2022-38745
DescriptionApache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3526-1, ELA-968-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libreoffice (PTS)jessie, jessie (lts)1:4.3.3-2+deb8u15vulnerable
stretch (security)1:5.2.7-1+deb9u11vulnerable
stretch (lts), stretch1:6.1.5-3~deb9u2fixed
buster1:6.1.5-3+deb10u7vulnerable
buster (security)1:6.1.5-3+deb10u11fixed
bullseye1:7.0.4-4+deb11u8fixed
bullseye (security)1:7.0.4-4+deb11u9fixed
bookworm4:7.4.7-1+deb12u1fixed
bookworm (security)4:7.4.7-1+deb12u2fixed
sid, trixie4:24.2.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libreofficesourcejessie(unfixed)end-of-life
libreofficesourcestretch1:6.1.5-3~deb9u1ELA-968-1
libreofficesourcebuster1:6.1.5-3+deb10u10DLA-3526-1
libreofficesourcebullseye1:7.0.4-4+deb11u6
libreofficesource(unstable)1:7.3.1-1

Notes

https://cgit.freedesktop.org/libreoffice/core/commit/?id=5e8f64e50f97d39e83a3358697be14db03566878
https://www.libreoffice.org/about-us/security/advisories/CVE-2022-38745
[jessie] - libreoffice <end-of-life> (GUI/non-headless not supported, too risky to backport, massive internal library changes, attack vector is rather local)

Search for package or bug name: Reporting problems