PT-2021-4369 · Document Foundation+6 · Libreoffice+6

Published

2021-10-11

·

Updated

2025-03-21

·

CVE-2021-25635

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions LibreOffice (affected versions not specified)
Description The issue is related to errors in cryptographic signature verification. It may allow a remote attacker to conduct spoofing attacks. The flaw leads to LibreOffice presenting a valid signature when the validity of the signature was not verified, posing a threat to confidentiality and integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Verification of Cryptographic Signature

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1766
ALT-PU-2021-3043
ALT-PU-2021-3077
BDU:2021-04999
CESA-2022_1766
CVE-2021-25635
MGASA-2021-0471
RHSA-2022:1766
RHSA-2022_1766
RLSA-2022:1766

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Libreoffice
Red Hat
Rocky Linux