Логотип exploitDog
bind:CVE-2021-25636
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-25636

Количество 11

Количество 11

ubuntu логотип

CVE-2021-25636

больше 3 лет назад

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-25636

больше 3 лет назад

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2021-25636

больше 3 лет назад

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-25636

больше 3 лет назад

LibreOffice supports digital signatures of ODF documents and macros wi ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0886-1

больше 3 лет назад

Security update for libreoffice

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1093-1

больше 3 лет назад

Security update for libreoffice

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0886-1

больше 3 лет назад

Security update for libreoffice

EPSS: Низкий
rocky логотип

RLSA-2022:7461

почти 3 года назад

Moderate: libreoffice security update

EPSS: Низкий
github логотип

GHSA-3cgr-wxhv-h7xw

больше 3 лет назад

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2022-7461

больше 2 лет назад

ELSA-2022-7461: libreoffice security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2022-02189

больше 4 лет назад

Уязвимость пакета офисных программ LibreOffice, связанная с некорректной проверкой криптографической подписи, позволяющая нарушителю обойти ограничения безопасности

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-25636

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2021-25636

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 6.2
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-25636

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-25636

LibreOffice supports digital signatures of ODF documents and macros wi ...

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0886-1

Security update for libreoffice

0%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1093-1

Security update for libreoffice

0%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0886-1

Security update for libreoffice

0%
Низкий
больше 3 лет назад
rocky логотип
RLSA-2022:7461

Moderate: libreoffice security update

0%
Низкий
почти 3 года назад
github логотип
GHSA-3cgr-wxhv-h7xw

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2022-7461

ELSA-2022-7461: libreoffice security update (MODERATE)

больше 2 лет назад
fstec логотип
BDU:2022-02189

Уязвимость пакета офисных программ LibreOffice, связанная с некорректной проверкой криптографической подписи, позволяющая нарушителю обойти ограничения безопасности

CVSS3: 6.3
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу