PT-2025-18010 · Document Foundation+5 · Libreoffice+5

Juraj Šarinay

·

Published

2025-04-27

·

Updated

2025-12-15

·

CVE-2025-2866

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LibreOffice versions 24.8 through 24.8.5 LibreOffice versions 25.2 through 25.2.1
Description The issue is related to an Improper Verification of Cryptographic Signature, allowing PDF Signature Spoofing by Improper Validation. A flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid.
Recommendations For LibreOffice versions 24.8 through 24.8.5, update to version 24.8.6 or later. For LibreOffice versions 25.2 through 25.2.1, update to version 25.2.2 or later.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-7908
BDU:2025-05910
CVE-2025-2866
DLA-4205-1
DSA-5908-1
MGASA-2025-0154
USN-7504-1

Affected Products

Alt Linux
Astra Linux
Debian
Libreoffice
Linuxmint
Ubuntu