¡¾Îó²îͨ¸æ¡¿Apache OpenOffice 10Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-10-120x00 Îó²î¸ÅÊö
2021Äê10ÔÂ11ÈÕ£¬£¬£¬ApacheÐû²¼Ç徲ͨ¸æ£¬£¬£¬¹ûÕæÅû¶ÁËApache OpenOfficeÖеĶà¸öÇå¾²Îó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÀ´ÓÕÆÊðÃûÎĵµ»òʵÑéδÊÚȨ²Ù×÷¡£¡£¡£
0x01 Îó²îÏêÇé
Apache OpenOffice ºÍ LibreOffice ¶¼ ÊÇOpenOffice.orgµÄÑÜÉú²úÆ·¡£¡£¡£Apache openofficeÊÇÒ»¿îÀàËÆÓÚ΢ÈíMS OfficeÈí¼þºÍWPSµÄÃâ·Ñ¿çƽ̨µÄ°ì¹«Èí¼þÌ×¼þ£»£»£»£»LibreOffice°ì¹«Ì×¼þͬÑùÊÇ×ÔÓÉ¿ªÔ´µÄ£¬£¬£¬µ«Ïà±ÈOpenOfficeÔöÌíÁËÐí¶àÌØÉ«¹¦Ð§¡£¡£¡£
×÷ΪOpenOffice µÄÒ»¸ö·ÖÖ§£¬£¬£¬±¾´ÎÅû¶µÄ3¸öÎó²îÒ²Ó°ÏìÁËLibreOffice£º
CVE-2021-41830£ºApache OpenOffice£¨¸ßΣ£©
¹¥»÷ÕßÄܹ»ÐÞ¸ÄÒÑÊðÃûµÄÎļþºÍºê£¬£¬£¬Ê¹Æä¿´ÆðÀ´ÏñÊÇÀ´×ÔÊÜÐÅÈεÄȪԴ¡£¡£¡£¸ÃÎó²îÒ²Ó°ÏìÁËLibreOffice£¬£¬£¬×·×ÙΪCVE-2021-25633¡£¡£¡£
CVE-2021-41831£ºApache OpenOffice£¨ÖÐΣ£©
¹¥»÷ÕßÄܹ»ÐÞ¸ÄÊðÃûÎĵµµÄʱ¼ä´Á¡£¡£¡£¸ÃÎó²îÒ²Ó°ÏìÁËLibreOffice£¬£¬£¬×·×ÙΪCVE-2021-25634¡£¡£¡£
CVE-2021-41832£ºApache OpenOffice£¨ÖÐΣ£©
¹¥»÷ÕßÐÞ¸ÄÎļþʹÆä¿´ÆðÀ´ÊÇÓÉÒ»¸öÊÜÐÅÈεÄȪԴǩÊðµÄ¡£¡£¡£¸ÃÎó²îÒ²Ó°ÏìÁËLibreOffice£¬£¬£¬×·×ÙΪCVE-2021-25635¡£¡£¡£
Ó°Ïì¹æÄ£
Apache OpenOffice < 4.1.10
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚApache OpenOfficeÒѾÐÞ¸´ÁËÕâЩÎó²î£¬£¬£¬½¨ÒéÏà¹ØÓû§ÊµÊ±Éý¼¶¸üÐÂÖÁApache OpenOffice 4.1.11°æ±¾£»£»£»£»Õë¶ÔLibreOffice£¬£¬£¬½¨ÒéÉý¼¶¸üе½7.0.5»ò7.1.1¼°¸ü¸ß°æ±¾¡£¡£¡£ÓÉÓÚÕâÁ½¸öÓ¦ÓóÌÐò¾ù²»Ìṩ×Ô¶¯¸üУ¬£¬£¬½¨ÒéÓû§ÏÂÔØ×îа汾ÊÖ¶¯¸üУ¬£¬£¬»òÕßÑ¡ÔñÍêÈ«½ûÓð칫Ì×¼þÉϵĺ깦ЧÒÔ»º½â´ËÎó²î¡£¡£¡£
ÏÂÔØÁ´½Ó£º
Apache OpenOffice£º
https://www.openoffice.org/download/
LibreOffice£º
https://www.libreoffice.org/download/download/
0x03 ²Î¿¼Á´½Ó
http://mail-archives.apache.org/mod_mbox/www-announce/202110.mbox/%3Caf529548-6884-590a-1d8f-e66e90bfb7f8@apache.org%3E
https://www.bleepingcomputer.com/news/security/libreoffice-openoffice-bug-allows-hackers-to-spoof-signed-docs/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41832
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-10-12 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
CVSS£ºwww.first.org
NVD£ºnvd.nist.gov
0x06 ¹ØÓÚ¼øºÚµ£±£Íø
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º