Vulnerabilities in LibreOffice and Apache OpenOffice Allowing Bypass of Digital Signature Verification

Details have been revealed about three vulnerabilities in the office suites LibreOffice and Apache OpenOffice that allow attackers to prepare documents that appear to be signed by a trusted source or alter the date of an already signed document. The issues were addressed in the releases Apache OpenOffice 4.1.11 and LibreOffice 7.0.6/7.1.2 under the guise of non-security-related bugs (the LibreOffice 7.0.6 and 7.1.2 releases were published in early May, but information about the vulnerability was disclosed only now).

  • CVE-2021-41832, CVE-2021-25635 – allows an attacker to sign an ODF document with an untrusted self-signed certificate, but by altering the digital signature algorithm to an incorrect or unsupported value, achieve the display of this document as trusted (the signature with an incorrect algorithm was processed as valid).
  • CVE-2021-41830, CVE-2021-25633 – allows an attacker by merging data in documentsignatures.xml and macrosignatures.xml signed by different certificates to create an ODF document or macro that will appear in the interface as trusted, despite the presence of additional content certified by another certificate.
  • CVE-2021-41831, CVE-2021-25634 – allows modifications to be made to a digitally signed ODF document, distorting the time displayed to the user for the creation of the digital signature without violating the trust indication.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster