Логотип exploitDog
bind:"BDU:2022-02189" OR bind:"CVE-2021-25636"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2022-02189" OR bind:"CVE-2021-25636"

Количество 11

Количество 11

fstec логотип

BDU:2022-02189

около 5 лет назад

Уязвимость пакета офисных программ LibreOffice, связанная с некорректной проверкой криптографической подписи, позволяющая нарушителю обойти ограничения безопасности

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2021-25636

почти 4 года назад

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-25636

почти 4 года назад

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2021-25636

почти 4 года назад

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-25636

почти 4 года назад

LibreOffice supports digital signatures of ODF documents and macros wi ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0886-1

почти 4 года назад

Security update for libreoffice

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1093-1

почти 4 года назад

Security update for libreoffice

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0886-1

почти 4 года назад

Security update for libreoffice

EPSS: Низкий
rocky логотип

RLSA-2022:7461

около 3 лет назад

Moderate: libreoffice security update

EPSS: Низкий
github логотип

GHSA-3cgr-wxhv-h7xw

почти 4 года назад

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2022-7461

около 3 лет назад

ELSA-2022-7461: libreoffice security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2022-02189

Уязвимость пакета офисных программ LibreOffice, связанная с некорректной проверкой криптографической подписи, позволяющая нарушителю обойти ограничения безопасности

CVSS3: 6.3
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2021-25636

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2021-25636

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 6.2
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-25636

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
debian логотип
CVE-2021-25636

LibreOffice supports digital signatures of ODF documents and macros wi ...

CVSS3: 7.5
0%
Низкий
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2022:0886-1

Security update for libreoffice

0%
Низкий
почти 4 года назад
suse-cvrf логотип
SUSE-SU-2022:1093-1

Security update for libreoffice

0%
Низкий
почти 4 года назад
suse-cvrf логотип
SUSE-SU-2022:0886-1

Security update for libreoffice

0%
Низкий
почти 4 года назад
rocky логотип
RLSA-2022:7461

Moderate: libreoffice security update

0%
Низкий
около 3 лет назад
github логотип
GHSA-3cgr-wxhv-h7xw

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
oracle-oval логотип
ELSA-2022-7461

ELSA-2022-7461: libreoffice security update (MODERATE)

около 3 лет назад

Уязвимостей на страницу