Improper Verification of Cryptographic Signature...
Low severity
Unreviewed
Published
Apr 27, 2025
to the GitHub Advisory Database
•
Updated May 12, 2025
Description
Published by the National Vulnerability Database
Apr 27, 2025
Published to the GitHub Advisory Database
Apr 27, 2025
Last updated
May 12, 2025
Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation.
In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid
This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.
References