CVE-2021-25633

Severity
7.5HIGH
EPSS
0.5%
top 32.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11
Latest updateMar 13

Description

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to combine multiple certificate data, which when opened caused LibreOff

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

CVEListV5the_document_foundation/libreoffice7-07.0.6+1
NVDlibreoffice/libreoffice7.0.07.0.6+1
Debianlibreoffice< 1:7.0.4-4+deb11u1+3
CVEListV5apache_software_foundation/apache_openofficeApache OpenOffice4.1.10+1

Also affects: Debian Linux 11.0

🔴Vulnerability Details

4
OSV
resteasy vulnerabilities2025-03-13
GHSA
GHSA-fx8r-3hmx-c78j: LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurr2022-05-24
CVEList
Content Manipulation with Double Certificate Attack2021-10-11
OSV
CVE-2021-25633: LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurr2021-10-11

📋Vendor Advisories

3
Ubuntu
LibreOffice vulnerabilities2021-11-22
Red Hat
libreoffice: Content Manipulation with Double Certificate Attack2021-10-11
Debian
CVE-2021-25633: libreoffice - LibreOffice supports digital signatures of ODF documents and macros within docum...2021

💬Community

1
Bugzilla
CVE-2020-25633 resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client's WebApplicationException handling2020-09-15
CVE-2021-25633 (HIGH CVSS 7.5) | LibreOffice supports digital signat | cvebase.io