https://seclists.org/oss-sec/2023/q4/345: CVE-2022-43680: Apache OpenOffice: "Use after free" fixed in libexpat
Published Dec 28, 2023
·Updated
Affected Software
2 affected components
Apache OpenOffice<=4.1.15
Apache libexpat<=2.4.9
Frequently Asked Questions
1
What is the severity of CVE-2022-43680?
The severity of CVE-2022-43680 is rated as moderate.
2
What versions of Apache OpenOffice are affected by CVE-2022-43680?
Apache OpenOffice versions up to and including 4.1.15 are affected by CVE-2022-43680.
3
What causes the vulnerability CVE-2022-43680?
CVE-2022-43680 is caused by a use-after-free vulnerability due to overeager destruction of a shared DTD in libexpat.
4
How can I mitigate the risks associated with CVE-2022-43680?
To mitigate the risks associated with CVE-2022-43680, upgrade to a fixed version of Apache OpenOffice beyond 4.1.15.
5
What component does CVE-2022-43680 affect?
CVE-2022-43680 affects the libexpat component used in Apache OpenOffice.