Document Foundation · Libreoffice · CVE-2024-7788
**Name of the Vulnerable Software and Affected Versions**
LibreOffice versions prior to 24.2.5
**Description**
The issue affects the Zip Repair Mode of LibreOffice, where an improper digital signature invalidation vulnerability allows for signature forgery. This means an attacker could create a specially crafted document that, after repair, would report a valid electronic signature status, potentially deceiving users about the document's authenticity.
**Recommendations**
For versions prior to 24.2.5, update to version 24.2.5 or later to resolve the issue.
As a temporary workaround, consider avoiding the use of the Zip Repair Mode until a patch is applied.
Restrict access to documents that have been repaired using the vulnerable mode to minimize the risk of exploitation.