#VU57214 Improper Certificate Validation in LibreOffice - CVE-2021-25633
Published: October 11, 2021
LibreOffice
LibreOffice
Description
The vulnerability allows a remote user to perform spoofing attack.
The vulnerability exists due to application does not properly check for digital signatures of ODF files. A remote attacker can create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to combine multiple certificate data, which when opened caused LibreOffice to display a validly signed indicator but whose content was unrelated to the signature shown.