CVE-2025-64407 (CNNVD-202511-1495)
中文标题:
Apache OpenOffice 安全漏洞
英文标题:
Apache OpenOffice: URL fetching can be used to exfiltrate arbitrary INI file values and environment variables
漏洞描述
中文描述:
Apache OpenOffice是美国阿帕奇(Apache)基金会的一款开源的办公软件套件。该套件包含文本文档、电子表格、演示文稿、绘图、数据库等。 Apache OpenOffice 4.1.15及之前版本存在安全漏洞,该漏洞源于缺少授权检查,可能导致外部链接被自动加载并传输系统信息。
英文描述:
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. Such links could also be used to transmit system information, such as environment variables or configuration settings. In the affected versions of Apache OpenOffice, documents that used a certain URI scheme linking to external files would load the contents of such files without prompting the user for permission to do so. Such URI scheme allows to include system configuration data, that is not supposed to be transmitted externally. This issue affects Apache OpenOffice: through 4.1.15. Users are recommended to upgrade to version 4.1.16, which fixes the issue. The LibreOffice suite reported this issue as CVE-2024-12426.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Apache Software Foundation | Apache OpenOffice | - | ≤ 4.1.15 | - |
cpe:2.3:a:apache_software_foundation:apache_openoffice:*:*:*:*:*:*:*:*
|
| apache | openoffice | * | - | - |
cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (adp)
MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-64407 |
2025-11-15 03:17:46 | 2026-01-12 02:12:18 |
| NVD | nvd_CVE-2025-64407 |
2025-11-14 03:00:08 | 2026-01-12 02:28:00 |
| CNNVD | cnnvd_CNNVD-202511-1495 |
2026-01-15 01:52:30 | 2026-01-15 01:52:58 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202511-1495
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 2
- data_sources: ['cve'] -> ['cve', 'nvd']