[$] The odd saga of CVE-2012-5639
A new releasefor any project with a fix for a12-year old CVE is going to standout pretty obviously; a recent release has a fix of that nature, but the trail of CVE-2012-5639 israther elusive. The ApacheOpenOffice project made its 4.1.15release with fixes for four CVEs, including one forCVE-2012-5639 ("Loading internal / external resources withoutwarning"), on December22. But nearly everything about that CVEseems rather murky, and it is difficult to get a clear picture of what,exactly, was done in OpenOffice to address the problem.