LibreOffice
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*
- >= 24.8, < 24.8.6
- >= 25.2, < 25.2.2
A vulnerability allowing PDF signature spoofing has been identified in LibreOffice versions 24.8 prior to 24.8.6 and 25.2 prior to 25.2.2. This issue arises from improper verification of cryptographic signatures, specifically in the handling of adbe.pkcs7.sha1 signatures, where invalid signatures could be incorrectly accepted as valid.
Exploitation of this vulnerability allows for the forgery of PDF signatures, with invalid signatures being accepted as legitimate.
Users are advised to upgrade to LibreOffice versions 24.8.6 or 25.2.2.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.