Freeoffice 2024 .deb postinst script is broken and dangerous

General questions and answers about FreeOffice 2024 for Linux. Don't post application-specific questions here, but in the appropriate subforum.
Post Reply
jjaakkol
Posts: 2
Joined: Tue Dec 09, 2025 2:21 pm

Freeoffice 2024 .deb postinst script is broken and dangerous

Post by jjaakkol »

Greetings from University of Helsinki! I am a Linux admin here.

Our users requested that I install FreeOffice 2024 in our Linux hosts. I installed the deb package and found out that the install script:

- Creates files in /tmp with known paths, which is a security hole if users precreate symlinks in /tmp to overwrite system files
- Runs script as regular users to install something in users home directorie. I am a system admin here and I am not allowed to do that. If the user's directories are on a NFS share, they wouldn't even be writeable.
- Modifies the system installation, at least the installed themes
- If uninstalled by apt purge won't properly remove the system modifications

Here you can see that it left its own system files writable by a local user, at least in /var/lib/dpk/dpkg directory:

root@lx4-907-31161:/var/lib/dpkg/info# ls -l *softmaker-free*
-rw-r--r-- 1 root root 25250 Dec 9 14:59 softmaker-freeoffice-2024.list
-rw-r--r-- 1 root root 41890 Dec 9 14:59 softmaker-freeoffice-2024.md5sums
-rwxr-xr-x 1 it4science it4science 56642 Sep 6 08:01 softmaker-freeoffice-2024.postinst
-rwxr-xr-x 1 it4science it4science 1515 Sep 6 08:01 softmaker-freeoffice-2024.prerm
root@lx4-907-31161:/var/lib/dpkg/info#

So, after this I will now need to reinstall my own Linux machine, since I have no idea what has happened to my system. I refuse install this by default for our users and I recommend to our users (and everyone else) that they won't do it either.

I think you should just remove your softmaker-freeoffice-2024.postinst script completely. The software would work fine without touching the rest of system, like all other software does. It is ok to touch user's files only if the user has started the software herself.

I'll be now reinstalling my own Linux system, since I have no idea what exactly was modified and reinstalling this is quicker done than trying to find out.
jjaakkol
Posts: 2
Joined: Tue Dec 09, 2025 2:21 pm

Re: Freeoffice 2024 .deb postinst script is broken and dangerous

Post by jjaakkol »

Apparently the installer overwrote all system office document icons with its own. That is not nice.
Post Reply

Return to “FreeOffice 2024 for Linux (General)”