VDB

CVE-2021-25636

CVE-2021-25636 PUBLISHED CVSS 7.5 HIGH

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.

EPSS 0.95% · 58.9th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.95%
58.9th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlibreoffice*, *, 0
Ubuntu:18.04:LTSlibreoffice1:5.4.1-0ubuntu3, 1:5.4.2-0ubuntu5, 1:6.0.2-0ubuntu1

Timeline

  • Feb 22, 2022 CVE Published
  • Feb 23, 2022 EPSS Score
  • Apr 16, 2022 EPSS Score
  • Jun 7, 2022 EPSS Score
  • Jul 30, 2022 EPSS Score
  • Sep 20, 2022 EPSS Score
  • Nov 12, 2022 EPSS Score
  • Jan 3, 2023 EPSS Score
  • Feb 24, 2023 EPSS Score
  • Apr 17, 2023 EPSS Score
  • Jun 8, 2023 EPSS Score
  • Jul 30, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›