Apache OpenOffice Weak Master Keys
Published Aug 13, 2022
8.8
HIGHCVSS 3.1
EPSS 1.77%
Description
Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the stored passwords vulnerable to a brute force attack if an attacker has access to the users stored config. This issue affects: Apache OpenOffice versions prior to 4.1.13. Reference: CVE-2022-26307 - LibreOffice
Affected products
-
- Version Apache OpenOffice 4StatusaffectedConstraints<4.1.13
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache OpenOffice | n/a |
|
- < 4.1.13
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- http://www.openwall.com/lists/oss-security/2022/08/13/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-40034 Advisory
- https://www.openoffice.org/security/cves/CVE-2022-37401.html x_refsource_MISCMitigationPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2022/08/13/2 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-40034 | Advisory | |
| https://www.openoffice.org/security/cves/CVE-2022-37401.html | x_refsource_MISCMitigationPatchVendor Advisory |
Change history (0)
No recorded changes yet.