PT-2021-7389 · Document Foundation+8 · Libreoffice+8

Published

2021-05-17

·

Updated

2022-05-10

·

CVE-2021-25634

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions LibreOffice versions 7.0.0 through 7.0.5 LibreOffice versions 7.1.0 through 7.1.1
Description The issue is related to an Improper Certificate Validation vulnerability in LibreOffice, which supports digital signatures of ODF documents and macros within documents. This vulnerability allowed an attacker to modify a digitally signed ODF document to insert an additional signing time timestamp, which LibreOffice would incorrectly present as a valid signature signed at the bogus signing time. The vulnerability can be exploited by a remote attacker to impact the integrity of data.
Recommendations For LibreOffice versions 7.0.0 through 7.0.5, update to version 7.0.6 or later. For LibreOffice versions 7.1.0 through 7.1.1, update to version 7.1.2 or later. As a temporary workaround, consider disabling the digital signature validation feature until a patch is available. Restrict access to digitally signed documents to minimize the risk of exploitation.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1766
ALT-PU-2021-1816
ALT-PU-2021-1843
ALT-PU-2021-1847
ALT-PU-2021-2151
ALT-PU-2021-3043
ALT-PU-2021-3077
BDU:2022-05923
CESA-2022_1766
CVE-2021-25634
DSA-4988-1
MGASA-2021-0471
RHSA-2022:1766
RHSA-2022_1766
RLSA-2022:1766
USN-5153-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Libreoffice
Linuxmint
Red Hat
Rocky Linux
Ubuntu