The Document Foundation has announced the release of corrective updates for the free office suite LibreOffice 7.2.4 and 7.1.8, in which the bundled cryptographic library NSS has been updated to version 3.73.0. This update addresses a critical vulnerability in NSS (CVE-2021-43527) that can be exploited through LibreOffice. The vulnerability allows for the execution of arbitrary code when verifying a specially crafted digital signature of a document. The releases are categorized as hotfixes and only contain this single change. Installation packages are available for Linux, macOS, and Windows platforms.
Source: opennet.ru