This is an automated email from the ASF dual-hosted git repository.

dave2wave pushed a commit to branch dave2wave-patch-2
in repository https://gitbox.apache.org/repos/asf/openoffice-org.git

commit 67c5e2dad5b6060adf83b390d7fac96119d91501
Author: Dave Fisher <[email protected]>
AuthorDate: Fri Oct 2 10:12:37 2026 -0700

    Bulletin
---
 content/security/cves/CVE-2026-59265.md | 43 +++++++++++++++++++++++++++++++++
 1 file changed, 43 insertions(+)

diff --git a/content/security/cves/CVE-2026-59265.md 
b/content/security/cves/CVE-2026-59265.md
new file mode 100644
index 0000000000..2bc31dbe55
--- /dev/null
+++ b/content/security/cves/CVE-2026-59265.md
@@ -0,0 +1,43 @@
+type=cve
+cve=CVE-2026-59265
+cvedesc=Opening a malicious document can lead to system takeover
+tags=weekly links, java
+status=published
+~~~~~~
+
+**Description**
+
+A code execution issue in the Java integration in Apache OpenOffice allows a 
crafted untrusted document to trigger the execution of arbitrary, even remote, 
code when it is opened by the user.
+
+This issue affects Apache OpenOffice: through 4.1.16.
+
+This issue is expected to be fixed in version 4.1.17, which is in the release 
candidate phase. Once 4.1.17 is released, users are recommended to upgrade to 
that version, which fixes the issue.
+
+The LibreOffice suite reported this issue as CVE-2026-63277.
+
+**Severity: Critical**
+
+Thanks to the reporters for discovering this issue.
+
+**Vendor: The Apache Software Foundation**
+
+**Versions Affected**
+
+All Apache OpenOffice versions 4.1.16 and older are affected.  
+OpenOffice.org versions may also be affected.
+
+**Mitigation**
+
+Until 4.1.17 is released, users can mitigate this issue by disabling the Java 
runtime integration: choose *Tools - Options - OpenOffice - Java* (*OpenOffice 
- Preferences - OpenOffice - Java* on macOS) and untick *Use a Java runtime 
environment*. This prevents the attack. If this is not possible, or as an extra 
precaution, avoid opening untrusted files entirely.
+
+Once released, install Apache OpenOffice 4.1.17 for the latest maintenance and 
cumulative security fixes. Use the Apache OpenOffice [download 
page](https://www.openoffice.org/download/).
+
+**Acknowledgements**
+
+The Apache OpenOffice Security Team would like to thank Rick de Jager of the 
V12 security team, and Thomas Rinsma and Edoardo Geraci of Codean Labs, who 
independently discovered and reported this issue.
+
+**Further Information**
+
+For additional information and assistance, consult the [Apache OpenOffice 
Community Forums](https://forum.openoffice.org/) or make requests to the 
[email protected] public mailing list.
+
+The latest information on Apache OpenOffice security bulletins can be found at 
the [Bulletin Archive](https://www.openoffice.org/security/bulletin.html) page.

Reply via email to