Логотип exploitDog
bind:CVE-2021-25636
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-25636

Количество 11

Количество 11

ubuntu логотип

CVE-2021-25636

почти 4 года назад

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-25636

почти 4 года назад

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2021-25636

почти 4 года назад

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-25636

почти 4 года назад

LibreOffice supports digital signatures of ODF documents and macros wi ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0886-1

почти 4 года назад

Security update for libreoffice

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1093-1

почти 4 года назад

Security update for libreoffice

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0886-1

почти 4 года назад

Security update for libreoffice

EPSS: Низкий
rocky логотип

RLSA-2022:7461

больше 3 лет назад

Moderate: libreoffice security update

EPSS: Низкий
github логотип

GHSA-3cgr-wxhv-h7xw

почти 4 года назад

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2022-7461

около 3 лет назад

ELSA-2022-7461: libreoffice security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2022-02189

около 5 лет назад

Уязвимость пакета офисных программ LibreOffice, связанная с некорректной проверкой криптографической подписи, позволяющая нарушителю обойти ограничения безопасности

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-25636

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2021-25636

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 6.2
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-25636

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
debian логотип
CVE-2021-25636

LibreOffice supports digital signatures of ODF documents and macros wi ...

CVSS3: 7.5
0%
Низкий
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2022:0886-1

Security update for libreoffice

0%
Низкий
почти 4 года назад
suse-cvrf логотип
SUSE-SU-2022:1093-1

Security update for libreoffice

0%
Низкий
почти 4 года назад
suse-cvrf логотип
SUSE-SU-2022:0886-1

Security update for libreoffice

0%
Низкий
почти 4 года назад
rocky логотип
RLSA-2022:7461

Moderate: libreoffice security update

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cgr-wxhv-h7xw

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
oracle-oval логотип
ELSA-2022-7461

ELSA-2022-7461: libreoffice security update (MODERATE)

около 3 лет назад
fstec логотип
BDU:2022-02189

Уязвимость пакета офисных программ LibreOffice, связанная с некорректной проверкой криптографической подписи, позволяющая нарушителю обойти ограничения безопасности

CVSS3: 6.3
0%
Низкий
около 5 лет назад

Уязвимостей на страницу