CVE-2005-4636: Medium severity OpenOffice OpenOffice vulnerability
Published Dec 31, 2005
·Updated
OpenOffice.org 2.0 and earlier, when hyperlinks has been disabled, does not prevent the user from clicking the WWW-browser button in the Hyperlink dialog, which makes it easier for attackers to trick the user into bypassing intended security settings.
Affected Software
9 affected components
OpenOffice OpenOffice=1.0.1
OpenOffice OpenOffice=1.0.2
OpenOffice OpenOffice=1.1.0
OpenOffice OpenOffice=1.1.1
OpenOffice OpenOffice=1.1.2
OpenOffice OpenOffice=1.1.3
OpenOffice OpenOffice=1.1.4
OpenOffice OpenOffice=1.1.5
OpenOffice OpenOffice=2.0
Remediation
Patch Available
Event History
Dec 31, 2005
CVE Published
05:00 AM
Jan 10, 2006
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-4636?
CVE-2005-4636 is considered a moderate severity vulnerability.
2
How do I fix CVE-2005-4636?
To fix CVE-2005-4636, disable the browser button in the Hyperlink dialog or upgrade to a patched version of OpenOffice.
3
What software versions are affected by CVE-2005-4636?
CVE-2005-4636 affects OpenOffice.org versions 1.0.1, 1.0.2, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, and 2.0.
4
Why is CVE-2005-4636 a concern for users?
CVE-2005-4636 is concerning because it allows attackers to deceive users into bypassing security settings.
5
Is there a patch available for CVE-2005-4636?
Yes, users should upgrade to the latest version of OpenOffice to address CVE-2005-4636.