Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-2866

Опубликовано: 27 апр. 2025
Источник: redhat
CVSS3: 2.8
EPSS Низкий

Описание

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.

A flaw was found in LibreOffice related to cryptographic signature verification in PDFs. This vulnerability allows attackers to spoof digital signatures, possibly leading to misleading or falsified documents and potentially affecting trust in digitally signed PDFs.

Меры по смягчению последствий

Users should apply security updates to mitigate the risk.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreofficeFix deferred
Red Hat Enterprise Linux 7libreofficeFix deferred
Red Hat Enterprise Linux 8libreofficeFix deferred
Red Hat Enterprise Linux 9libreofficeFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2362574LibreOffice: PDF signature forgery with adbe.pkcs7.sha1 SubFilter

EPSS

Процентиль: 2%
0.00017
Низкий

2.8 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 месяца назад

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.

CVSS3: 5.5
nvd
3 месяца назад

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.

CVSS3: 5.5
debian
3 месяца назад

Improper Verification of Cryptographic Signature vulnerability in Libr ...

CVSS3: 9.8
github
3 месяца назад

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.

CVSS3: 9.8
fstec
3 месяца назад

Уязвимость пакета офисных программ LibreOffice, связанная с некорректной проверкой криптографической подписи, позволяющая нарушителю подделывать цифровые подписи

EPSS

Процентиль: 2%
0.00017
Низкий

2.8 Low

CVSS3