OpenOffice Vulnerable to Remote Code Execution, LibreOffice Patched
OpenOffice is exposed to a remote code execution vulnerability that can be triggered using automated macro execution when users move the mouse over a maliciously crafted ODT document.
The security issue affects all versions of OpenOffice, as well as all LibreOffice releases up to and including 6.0.6/6.1.6. The bug was patched by The Document Foundation in LibreOffice 6.0.7/6.1.3 after receiving a report from security researcher Alex Inführ.
However, at the time this article was published, OpenOffice 4.1.6 (the latest version ) is still vulnerable. Inführ says in his detailed description of the vulnerability that the bug affected both Linux and Windows versions of LibreOffice and that no warning dialog would be displayed after successful exploitation: "I started to have a look at LibreOffice and discovered a way to achieve remote code execution as soon as a user opens a malicious ODT file and moves his mouse over the document, without triggering any warning dialog."