- Description
- Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.
- Source
- security@documentfoundation.org
- NVD status
- Analyzed
CVSS 4.0
- Type
- Secondary
- Base score
- 2.4
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- LOW
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- Hype score
- Not currently trending
🚨 Breaking: #LibreOffice flaw (CVE-2025-2866) lets hackers forge PDF signatures! 📌 Affects Mageia, Debian, others. 🛠 Patch now: libreoffice-24.2.7.2 🔗 Details: 👉 https://t.co/PGzgOqk8DT #Infosec #LinuxSecurity https://t.co/wcumeD8bhM
@Cezar_H_Linux
11 May 2025
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Libreoffice CVE-2025-2866 Title: PDF signature forgery with adbe.pkcs7.sha1 SubFilter Fixed in: LibreOffice 24.8.6 and 25.2.2 https://t.co/crgS7Pmpoy
@TheUnicornXXL
30 Apr 2025
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-2866 PDF Signature Validation Bypass in LibreOffice Crypto Signature Verificat... https://t.co/HlY6FDbHl7 Vulnerability Notification: https://t.co/xhLrNnfyrO
@VulmonFeeds
27 Apr 2025
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BD405BA2-8F34-4357-BAB8-318569954069",
"versionEndExcluding": "24.8.6.0",
"versionStartIncluding": "24.8.0.1"
},
{
"criteria": "cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "86D26ABF-BF83-4C25-A31B-B15B17B708E4",
"versionEndExcluding": "25.2.2",
"versionStartIncluding": "25.2.0.1"
},
{
"criteria": "cpe:2.3:a:libreoffice:libreoffice:24.8.0.0:alpha1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "910F0BB3-ECA0-4338-B67B-A9BBD6FFDCB7"
},
{
"criteria": "cpe:2.3:a:libreoffice:libreoffice:24.8.0.0:beta1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A1C6BCA-6638-4925-A32B-217282923645"
},
{
"criteria": "cpe:2.3:a:libreoffice:libreoffice:25.2.0.0:alpha1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB7D3327-6D96-42FE-B4E2-0D6C44409D69"
},
{
"criteria": "cpe:2.3:a:libreoffice:libreoffice:25.2.0.0:beta1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E2AB7E83-11C6-4177-8796-57D476B24E1E"
}
],
"operator": "OR"
}
]
}
]