CVE-2021-25636 Information

Description

LibreOffice supports digital signatures of ODF documents and macros within documents presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both \X509Data\ and \KeyValue\ children of the \KeyInfo\ tag which when opened caused LibreOffice to verify using the \KeyValue\ but to report verification with the unrelated \X509Data\ value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Reference

https://www.libreoffice.org/about-us/security/advisories/CVE-2021-25636/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NE6UIBCPZWRBWPSEGJOPNWPPT3CCMVH2/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

7.5

Share on: