CVE detail
CVE-2021-28129 — CVE-2021-28129
Published 2021-10-07 · Modified 2026-06-17 · Vendor apache · Product openoffice · Source nvd
HIGH
severity
CVSS-derived band
0.0053
EPSS probability
exploitation probability, 30d
42.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could allow a crafted attack on files owned by that user or group if they exist. Users who installed the Apache OpenOffice 4.1.8 DEB packaging should upgrade to the latest version of Apache OpenOffice.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References