By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send the document back to the attacker. The vulnerability is mitigated by the need for the attacker to know the precise file path in the target system, and the need to trick the user into saving the document and sending it back.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: apache
Published: 2017-11-20T20:00:00Z
Updated: 2024-09-16T20:16:57.330Z
Reserved: 2016-12-05T00:00:00
Link: CVE-2017-3157
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Deferred
Published: 2017-11-20T20:29:00.543
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-3157
 Redhat
                        Redhat