PT-2021-5406 · Apache · Apache Openoffice+1
Christian Mainka
+3
·
Published
2021-09-23
·
Updated
2021-10-19
·
CVE-2021-41831
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache OpenOffice versions prior to 4.1.11
Description
The issue is related to errors in checking signed documents, which can be exploited by a remote attacker to compromise the integrity of information. It is possible for an attacker to manipulate the timestamp of signed documents.
Recommendations
For versions prior to 4.1.11, update to version 4.1.11 to resolve the issue. As a temporary workaround, consider restricting the use of signed documents until the update is applied.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Openoffice
Openoffice