Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-22mj-r7hq-f9h2

Опубликовано: 27 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2.4
CVSS3: 9.8

Описание

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation.

In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid

This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation.

In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid

This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.

EPSS

Процентиль: 2%
0.00017
Низкий

2.4 Low

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 месяца назад

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.

CVSS3: 2.8
redhat
3 месяца назад

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.

CVSS3: 5.5
nvd
3 месяца назад

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.

CVSS3: 5.5
debian
3 месяца назад

Improper Verification of Cryptographic Signature vulnerability in Libr ...

CVSS3: 9.8
fstec
3 месяца назад

Уязвимость пакета офисных программ LibreOffice, связанная с некорректной проверкой криптографической подписи, позволяющая нарушителю подделывать цифровые подписи

EPSS

Процентиль: 2%
0.00017
Низкий

2.4 Low

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-347