CVE-2021-25635
published 2025-03-21CVE-2021-25635: An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with a signature untrusted by the target…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.14%
3.3th percentile
An Improper Certificate Validation vulnerability in LibreOffice allowed
an attacker to self sign an ODF document, with a signature untrusted by
the target, then modify it to change the signature algorithm to an
invalid (or unknown to LibreOffice) algorithm and LibreOffice would incorrectly present such a signature with an unknown algorithm as a
valid signature issued by a trusted person
This issue affects LibreOffice: from 7.0 before 7.0.5, from 7.1 before 7.1.1.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | < 4.1.11 | 4.1.11 |
| apache_software_foundation | apache_openoffice | Apache OpenOffice – 4.1.10 | — |
| apache_software_foundation | apache_openoffice | OpenOffice.org – 3.4 | — |
| debian | libreoffice | — | — |
| libreoffice | libreoffice | >= 0 < 1:7.2.1-0ubuntu3 | 1:7.2.1-0ubuntu3 |
| libreoffice | libreoffice | >= 7.0.0 < 7.0.5.1 | 7.0.5.1 |
| libreoffice | libreoffice | 7.1.0.0 – 7.1.1.1 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv4.05.2MEDIUMCVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv5.2MEDIUM
vendor_debian5.2LOW
vendor_redhat5.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libreoffice: Content Manipulation with Certificate Validation Attack
vendor_redhat·2021-10-11·CVSS 5.2
CVE-2021-25635 [MEDIUM] CWE-295 libreoffice: Content Manipulation with Certificate Validation Attack
libreoffice: Content Manipulation with Certificate Validation Attack
An Improper Certificate Validation vulnerability in LibreOffice allowed
an attacker to self sign an ODF document, with a signature untrusted by
the target, then modify it to change the signature algorithm to an
invalid (or unknown to LibreOffice) algorithm and LibreOffice would incorrectly present such a signature with an unknown algorithm as a
valid signature issued by a trusted person
This issue affects LibreOffice: from 7.0 before 7.0.5, from 7.1 before 7.1.1.
A flaw was found in LibreOffice, where it improperly validated signatures for algorithms that were not verified. This flaw leads to LibreOffice presenting a valid signature when the validity of the signature was not verified. The highest threat from this vulner
Debian
CVE-2021-25635: libreoffice - An Improper Certificate Validation vulnerability in LibreOffice allowed an atta...
vendor_debian·2021·CVSS 5.2
CVE-2021-25635 [MEDIUM] CVE-2021-25635: libreoffice - An Improper Certificate Validation vulnerability in LibreOffice allowed an atta...
An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with a signature untrusted by the target, then modify it to change the signature algorithm to an invalid (or unknown to LibreOffice) algorithm and LibreOffice would incorrectly present such a signature with an unknown algorithm as a valid signature issued by a trusted person This issue affects LibreOffice: from 7.0 before 7.0.5, from 7.1 before 7.1.1.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-r73f-2rxh-prfm: An Improper Certificate Validation vulnerability in LibreOffice allowed
an attacker to self sign an ODF document, with a signature untrusted by
the ta
ghsa_unreviewed·2025-03-21
CVE-2021-25635 [MEDIUM] CWE-295 GHSA-r73f-2rxh-prfm: An Improper Certificate Validation vulnerability in LibreOffice allowed
an attacker to self sign an ODF document, with a signature untrusted by
the ta
An Improper Certificate Validation vulnerability in LibreOffice allowed
an attacker to self sign an ODF document, with a signature untrusted by
the target, then modify it to change the signature algorithm to an
invalid (or unknown to LibreOffice) algorithm and LibreOffice would incorrectly present such a signature with an unknown algorithm as a
valid signature issued by a trusted person
This issue affects LibreOffice: from 7.0 before 7.0.5, from 7.1 before 7.1.1.
OSV
CVE-2021-25635: An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with a signature untrusted by the ta
osv·2025-03-21·CVSS 5.2
CVE-2021-25635 [MEDIUM] CVE-2021-25635: An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with a signature untrusted by the ta
An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with a signature untrusted by the target, then modify it to change the signature algorithm to an invalid (or unknown to LibreOffice) algorithm and LibreOffice would incorrectly present such a signature with an unknown algorithm as a valid signature issued by a trusted person This issue affects LibreOffice: from 7.0 before 7.0.5, from 7.1 before 7.1.1.
GHSA
GHSA-72qv-v5c2-v52f: It is possible for an attacker to manipulate documents to appear to be signed by a trusted source
ghsa_unreviewed·2022-05-24·CVSS 5.2
CVE-2021-41832 [MEDIUM] CWE-347 GHSA-72qv-v5c2-v52f: It is possible for an attacker to manipulate documents to appear to be signed by a trusted source
It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25635 for the LibreOffice advisory.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-21
Published