Manifest files checksums for 4.1.16 are the same as for 4.1.16_rc3.
Release notes is available on [1].
Fixed in Apache OpenOffice 4.1.16 [2]:
CVE-2025-64401: Remote documents loaded without prompt via IFrame.
CVE-2025-64402: Remote documents loaded without prompt via OLE objects.
CVE-2025-64403: Remote documents loaded without prompt via "external data sources" in Calc.
CVE-2025-64404: Remote documents loaded without prompt via background and bullet images.
CVE-2025-64405: Remote documents loaded without prompt via DDE function.
CVE-2025-64406: Possible memory corruption during CSV import.
CVE-2025-64407: URL fetching can be used to exfiltrate arbitrary INI file values and environment variables.
[1] https://cwiki.apache.org/confluence/display/OOOUSERS/AOO+4.1.16+Release+Notes
[2] https://www.openoffice.org/security/bulletin.html
Signed-off-by: Sergey Torokhov <torokhov-s-a@yandex.ru>