PT-2021-4375 · Apache · Apache Openoffice+1

Christian Mainka

+3

·

Published

2021-09-23

·

Updated

2021-10-19

·

CVE-2021-41832

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache OpenOffice versions prior to 4.1.11
Description The issue is related to errors in cryptographic signature verification, allowing a remote attacker to modify the content of an ODF document. It is possible for an attacker to manipulate documents to appear to be signed by a trusted source.
Recommendations For versions prior to 4.1.11, update to version 4.1.11 to resolve the issue. As a temporary workaround, consider restricting the use of cryptographic signature verification features until the update is applied.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05005
CVE-2021-41832

Affected Products

Apache Openoffice
Openoffice