PT-2021-5406 · Apache · Apache Openoffice+1

Christian Mainka

+3

·

Published

2021-09-23

·

Updated

2021-10-19

·

CVE-2021-41831

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache OpenOffice versions prior to 4.1.11
Description The issue is related to errors in checking signed documents, which can be exploited by a remote attacker to compromise the integrity of information. It is possible for an attacker to manipulate the timestamp of signed documents.
Recommendations For versions prior to 4.1.11, update to version 4.1.11 to resolve the issue. As a temporary workaround, consider restricting the use of signed documents until the update is applied.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-06247
CVE-2021-41831

Affected Products

Apache Openoffice
Openoffice