This is an automated email from the ASF dual-hosted git repository. marcus pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/openoffice-org.git
commit 3fb29953b4dcc398e72f8fd51b0cbbfd211bf1cf Author: Marcus <[email protected]> AuthorDate: Mon Oct 11 15:39:46 2021 +0200 Security Bulletin for the Apache OpenOffice 4.1.11 Release --- content/security/bulletin.html | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/content/security/bulletin.html b/content/security/bulletin.html index ad121b4..aa5fc83 100644 --- a/content/security/bulletin.html +++ b/content/security/bulletin.html @@ -22,15 +22,19 @@ <h3>Fixed in Apache OpenOffice 4.1.11</h3> <ul> - <li><a href="cves/CVE-2021-28129.html">CVE-2021-28129</a>: DEB packaging installed with a non-root userid and groupid</li> - <li><a href="cves/CVE-2021-33035.html">CVE-2021-33035</a>: Buffer overflow from a crafted DBF file</li> - <li><a href="cves/CVE-2021-40439.html">CVE-2021-40439</a>: "Billion Laughs" fixed in Expat >=2.4.0</li> + <li><a href="cves/CVE-2021-28129.html">CVE-2021-28129</a>: DEB packaging installed with a non-root userid and groupid</li> + <li><a href="cves/CVE-2021-33035.html">CVE-2021-33035</a>: Buffer overflow from a crafted DBF file</li> + <li><a href="cves/CVE-2021-40439.html">CVE-2021-40439</a>: "Billion Laughs" fixed in Expat >=2.4.0</li> + <li><a href="cves/CVE-2021-41830.html">CVE-2021-41830</a>: #1 Content Manipulation with Certificate Double Attack</li> + <li><a href="cves/CVE-2021-41830.html">CVE-2021-41830</a>: #2 Macro Manipulation with Certificate Double Attack</li> + <li><a href="cves/CVE-2021-41831.html">CVE-2021-41831</a>: #3 Timestamp Manipulation with Signature Wrapping</li> + <li><a href="cves/CVE-2021-41832.html">CVE-2021-41832</a>: #4 Content Manipulation with Certificate Validation Attack</li> </ul> <h3>Fixed in Apache OpenOffice 4.1.10</h3> <ul> - <li><a href="cves/CVE-2021-30245.html">CVE-2021-30245</a>: Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks</li> + <li><a href="cves/CVE-2021-30245.html">CVE-2021-30245</a>: Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks</li> </ul> <h3>Fixed in Apache OpenOffice 4.1.8</h3>
