Improper Verification of Cryptographic Signature in LibreOffice - CVE-2025-2866
Published: April 28, 2025
Vulnerability identifier: #VU107968
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-2866
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to improper verification of adbe.pkcs7.sha1 signatures when handling PDF files. A remote attacker can present a document as valid despite not having a valid signature.
Affected software
LibreOffice
Debian Linux
Ubuntu
libreoffice (Ubuntu package)
libreoffice (Debian package)
Debian Linux
Ubuntu
libreoffice (Ubuntu package)
libreoffice (Debian package)
How to mitigate CVE-2025-2866
Install updates from vendor's website.
LibreOffice - addressed in versions 24.8.6.1, 25.2.2.1
libreoffice (Ubuntu package) - addressed in versions 1:6.4.7-0ubuntu0.20.04.15, 1:7.3.7-0ubuntu0.22.04.10, 4:24.2.7-0ubuntu0.24.04.4, 4:24.8.6-0ubuntu0.24.10.2
libreoffice (Debian package) - update to 4:7.4.7-1+deb12u8
libreoffice (Ubuntu package) - addressed in versions 1:6.4.7-0ubuntu0.20.04.15, 1:7.3.7-0ubuntu0.22.04.10, 4:24.2.7-0ubuntu0.24.04.4, 4:24.8.6-0ubuntu0.24.10.2
libreoffice (Debian package) - update to 4:7.4.7-1+deb12u8