CVE-2021-40439: Billion Laughs
Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denial of service attack and exploit via crafted XML files. ODF files consist of a set of XML files. All versions of Apache OpenOffice up to 4.1.10 are subject to this issue. expat in version 4.1.11 is patched.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache OpenOfficeto a version that resolves this vulnerability.Fixed in 4.1.11 - Upgrade
Upgrade
expatto a version that resolves this vulnerability.Fixed in 4.1.11
Event History
Frequently Asked Questions
What is CVE-2021-40439?
CVE-2021-40439 is a vulnerability in Apache OpenOffice that allows for a denial of service attack and exploit through crafted XML files.
What is the severity of CVE-2021-40439?
The severity of CVE-2021-40439 is medium with a severity value of 6.5.
How does CVE-2021-40439 affect Apache OpenOffice?
CVE-2021-40439 affects Apache OpenOffice versions prior to 4.1.10 by allowing a denial of service attack and exploit via crafted XML files.
How can I mitigate CVE-2021-40439?
To mitigate CVE-2021-40439, it is recommended to update to Apache OpenOffice version 4.1.10 or later, which fixes the vulnerability.
Where can I find more information about CVE-2021-40439?
You can find more information about CVE-2021-40439 at the following references: [Reference 1](http://www.openwall.com/lists/oss-security/2021/10/07/4), [Reference 2](https://lists.apache.org/thread.html/r41eca5f4f09e74436cbb05dec450fc2bef37b5d3e966aa7cc5fada6d@%3Cannounce.apache.org%3E), [Reference 3](https://lists.apache.org/thread.html/rfb2c193360436e230b85547e85a41bea0916916f96c501f5b6fc4702%40%3Cusers.openoffice.apache.org%3E)