CVE-2021-25633
published 2021-10-11CVE-2021-25633: LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.71%
49.7th percentile
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to combine multiple certificate data, which when opened caused LibreOffice to display a validly signed indicator but whose content was unrelated to the signature shown. This issue affects: The Document Foundation LibreOffice 7-0 versions prior to 7.0.6; 7-1 versions prior to 7.1.2.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | < 4.1.11 | 4.1.11 |
| apache_software_foundation | apache_openoffice | Apache OpenOffice – 4.1.10 | — |
| apache_software_foundation | apache_openoffice | OpenOffice.org – 3.4 | — |
| debian | debian_linux | — | — |
| debian | libreoffice | < libreoffice 1:7.2.0-2 (bookworm) | libreoffice 1:7.2.0-2 (bookworm) |
| libreoffice | libreoffice | >= 0 < 1:7.0.4-4+deb11u1 | 1:7.0.4-4+deb11u1 |
| libreoffice | libreoffice | >= 0 < 1:7.2.0-2 | 1:7.2.0-2 |
| libreoffice | libreoffice | >= 0 < 1:7.2.0-2 | 1:7.2.0-2 |
| libreoffice | libreoffice | >= 0 < 1:7.2.0-2 | 1:7.2.0-2 |
| libreoffice | libreoffice | >= 7.0.0 < 7.0.6 | 7.0.6 |
| libreoffice | libreoffice | >= 7.1.0 < 7.1.2 | 7.1.2 |
| redhat | resteasy | >= 0 < 3.6.2-2ubuntu0.20.04.1~esm1 | 3.6.2-2ubuntu0.20.04.1~esm1 |
| redhat | resteasy | >= 0 < 3.6.2-2ubuntu0.22.04.1~esm1 | 3.6.2-2ubuntu0.22.04.1~esm1 |
| redhat | resteasy | >= 0 < 3.6.2-2ubuntu0.24.04.1~esm1 | 3.6.2-2ubuntu0.24.04.1~esm1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LibreOffice vulnerabilities
vendor_ubuntu·2021-11-22
CVE-2021-25634 LibreOffice vulnerabilities
Title: LibreOffice vulnerabilities
Summary: LibreOffice could incorrectly validate document signatures.
It was discovered that LibreOffice incorrectly handled digital signatures.
An attacker could possibly use this issue to create a specially crafted
document that would display a validly signed indicator, contrary to
expectations.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libreoffice: Content Manipulation with Double Certificate Attack
vendor_redhat·2021-10-11·CVSS 7.5
CVE-2021-25633 [HIGH] CWE-295 libreoffice: Content Manipulation with Double Certificate Attack
libreoffice: Content Manipulation with Double Certificate Attack
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to combine multiple certificate data, which when opened caused LibreOffice to display a validly signed indicator but whose content was unrelated to the signature shown. This issue affects: The Document Foundation LibreOffice 7-0 versions prior to 7.0.6; 7-1 versions prior to 7.1.2.
LibreOffice improperl
Debian
CVE-2021-25633: libreoffice - LibreOffice supports digital signatures of ODF documents and macros within docum...
vendor_debian·2021·CVSS 7.5
CVE-2021-25633 [HIGH] CVE-2021-25633: libreoffice - LibreOffice supports digital signatures of ODF documents and macros within docum...
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to combine multiple certificate data, which when opened caused LibreOffice to display a validly signed indicator but whose content was unrelated to the signature shown. This issue affects: The Document Foundation LibreOffice 7-0 versions prior to 7.0.6; 7-1 versions prior to 7.1.2.
Scope: local
bookworm: resolved (fixed in 1:7.2.0-2)
bullseye: resolved (fixed in 1:7.0.
OSV
resteasy vulnerabilities
osv·2025-03-13·CVSS 6.1
CVE-2020-10688 resteasy vulnerabilities
resteasy vulnerabilities
Nikos Papadopoulos discovered that RESTEasy improperly handled URL encoding
when certain errors occur. An attacker could possibly use this issue to
modify the app's behavior for other users through the network.
(CVE-2020-10688)
Mirko Selber discovered that RESTEasy improperly validated user input
during HTTP response construction. This issue could possibly allow an
attacker to cause a denial of service or execute arbitrary code.
(CVE-2020-1695)
It was discovered that RESTEasy unintentionally disclosed potentially
sensitive server information to users during the handling of certain
errors. (CVE-2020-25633)
It was discovered that RESTEasy unintentionally disclosed parts of its code
to users during the handling of certain errors. (CVE-2021-20289)
It was discovere
GHSA
GHSA-7qhr-g3xw-3692: It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2021-41830 [HIGH] CWE-347 GHSA-7qhr-g3xw-3692: It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source
It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25633 for the LibreOffice advisory.
GHSA
GHSA-fx8r-3hmx-c78j: LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurr
ghsa_unreviewed·2022-05-24
CVE-2021-25633 [HIGH] CWE-295 GHSA-fx8r-3hmx-c78j: LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurr
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to combine multiple certificate data, which when opened caused LibreOffice to display a validly signed indicator but whose content was unrelated to the signature shown. This issue affects: The Document Foundation LibreOffice 7-0 versions prior to 7.0.6; 7-1 versions prior to 7.1.2.
OSV
CVE-2021-25633: LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurr
osv·2021-10-11·CVSS 7.5
CVE-2021-25633 [HIGH] CVE-2021-25633: LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurr
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to combine multiple certificate data, which when opened caused LibreOffice to display a validly signed indicator but whose content was unrelated to the signature shown. This issue affects: The Document Foundation LibreOffice 7-0 versions prior to 7.0.6; 7-1 versions prior to 7.1.2.
No detection rules found.
No public exploits indexed.
2021-10-11
Published