Back to list
Vulnerable MSVC++ runtime distributed with LibreOffice 5.0.0 for Windows
Aug 05 2015 08:26PM
Stefan Kanthak (stefan kanthak nexgo de)
the just released latest version 220.127.116.11 of LibreOffice.org for Windows
distributes (once again) a completely outdated and vulnerable MSVC++
The installer package LibreOffice_5.0.0_Win_x86.msi contains the files
of the initial/RTM release of the MSVC++ Runtime 2005.
These DLLs have been updated serveral times since their initial release:
For general guidelines see <https://support.microsoft.com/kb/326922>
Since the libraries are installed in the application's own directory
they are NOT detected by "Windows Update Agent" (or tools like
"Secunia Personal Inspector") and are therefore NOT updated via
This is a well known problem, see <https://support.microsoft.com/kb/835322>,
but apparently LibreOffice.org doesn't seem to care!
I reported this error SEVERAL times in the past, for example see
JFTR: Windows Vista and later include NEWER versions of these DLLs,
there is absolutely no need to redistribute an ancient version
in your product at all (especially after Windows XP and 2003
have reached end-of-life)!
[ reply ]
Copyright 2010, SecurityFocus