Content Manipulation with Double Certificate Attack
Description
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to combine multiple certificate data, which when opened caused LibreOffice to display a validly signed indicator but whose content was unrelated to the signature shown. This issue affects: The Document Foundation LibreOffice 7-0 versions prior to 7.0.6; 7-1 versions prior to 7.1.2.
Affected products
172- osv-coords171 versionspkg:rpm/almalinux/autocorr-afpkg:rpm/almalinux/autocorr-bgpkg:rpm/almalinux/autocorr-capkg:rpm/almalinux/autocorr-cspkg:rpm/almalinux/autocorr-dapkg:rpm/almalinux/autocorr-depkg:rpm/almalinux/autocorr-enpkg:rpm/almalinux/autocorr-espkg:rpm/almalinux/autocorr-fapkg:rpm/almalinux/autocorr-fipkg:rpm/almalinux/autocorr-frpkg:rpm/almalinux/autocorr-gapkg:rpm/almalinux/autocorr-hrpkg:rpm/almalinux/autocorr-hupkg:rpm/almalinux/autocorr-ispkg:rpm/almalinux/autocorr-itpkg:rpm/almalinux/autocorr-japkg:rpm/almalinux/autocorr-kopkg:rpm/almalinux/autocorr-lbpkg:rpm/almalinux/autocorr-ltpkg:rpm/almalinux/autocorr-mnpkg:rpm/almalinux/autocorr-nlpkg:rpm/almalinux/autocorr-plpkg:rpm/almalinux/autocorr-ptpkg:rpm/almalinux/autocorr-ropkg:rpm/almalinux/autocorr-rupkg:rpm/almalinux/autocorr-skpkg:rpm/almalinux/autocorr-slpkg:rpm/almalinux/autocorr-srpkg:rpm/almalinux/autocorr-svpkg:rpm/almalinux/autocorr-trpkg:rpm/almalinux/autocorr-vipkg:rpm/almalinux/autocorr-zhpkg:rpm/almalinux/libreoffice-basepkg:rpm/almalinux/libreoffice-calcpkg:rpm/almalinux/libreoffice-corepkg:rpm/almalinux/libreoffice-datapkg:rpm/almalinux/libreoffice-drawpkg:rpm/almalinux/libreoffice-emailmergepkg:rpm/almalinux/libreoffice-filterspkg:rpm/almalinux/libreoffice-gdb-debug-supportpkg:rpm/almalinux/libreoffice-graphicfilterpkg:rpm/almalinux/libreoffice-gtk3pkg:rpm/almalinux/libreoffice-help-arpkg:rpm/almalinux/libreoffice-help-bgpkg:rpm/almalinux/libreoffice-help-bnpkg:rpm/almalinux/libreoffice-help-capkg:rpm/almalinux/libreoffice-help-cspkg:rpm/almalinux/libreoffice-help-dapkg:rpm/almalinux/libreoffice-help-depkg:rpm/almalinux/libreoffice-help-dzpkg:rpm/almalinux/libreoffice-help-elpkg:rpm/almalinux/libreoffice-help-enpkg:rpm/almalinux/libreoffice-help-espkg:rpm/almalinux/libreoffice-help-etpkg:rpm/almalinux/libreoffice-help-eupkg:rpm/almalinux/libreoffice-help-fipkg:rpm/almalinux/libreoffice-help-frpkg:rpm/almalinux/libreoffice-help-glpkg:rpm/almalinux/libreoffice-help-gupkg:rpm/almalinux/libreoffice-help-hepkg:rpm/almalinux/libreoffice-help-hipkg:rpm/almalinux/libreoffice-help-hrpkg:rpm/almalinux/libreoffice-help-hupkg:rpm/almalinux/libreoffice-help-idpkg:rpm/almalinux/libreoffice-help-itpkg:rpm/almalinux/libreoffice-help-japkg:rpm/almalinux/libreoffice-help-kopkg:rpm/almalinux/libreoffice-help-ltpkg:rpm/almalinux/libreoffice-help-lvpkg:rpm/almalinux/libreoffice-help-nbpkg:rpm/almalinux/libreoffice-help-nlpkg:rpm/almalinux/libreoffice-help-nnpkg:rpm/almalinux/libreoffice-help-plpkg:rpm/almalinux/libreoffice-help-pt-BRpkg:rpm/almalinux/libreoffice-help-pt-PTpkg:rpm/almalinux/libreoffice-help-ropkg:rpm/almalinux/libreoffice-help-rupkg:rpm/almalinux/libreoffice-help-sipkg:rpm/almalinux/libreoffice-help-skpkg:rpm/almalinux/libreoffice-help-slpkg:rpm/almalinux/libreoffice-help-svpkg:rpm/almalinux/libreoffice-help-tapkg:rpm/almalinux/libreoffice-help-trpkg:rpm/almalinux/libreoffice-help-ukpkg:rpm/almalinux/libreoffice-help-zh-Hanspkg:rpm/almalinux/libreoffice-help-zh-Hantpkg:rpm/almalinux/libreoffice-impresspkg:rpm/almalinux/libreofficekitpkg:rpm/almalinux/libreoffice-langpack-afpkg:rpm/almalinux/libreoffice-langpack-arpkg:rpm/almalinux/libreoffice-langpack-aspkg:rpm/almalinux/libreoffice-langpack-bgpkg:rpm/almalinux/libreoffice-langpack-bnpkg:rpm/almalinux/libreoffice-langpack-brpkg:rpm/almalinux/libreoffice-langpack-capkg:rpm/almalinux/libreoffice-langpack-cspkg:rpm/almalinux/libreoffice-langpack-cypkg:rpm/almalinux/libreoffice-langpack-dapkg:rpm/almalinux/libreoffice-langpack-depkg:rpm/almalinux/libreoffice-langpack-dzpkg:rpm/almalinux/libreoffice-langpack-elpkg:rpm/almalinux/libreoffice-langpack-enpkg:rpm/almalinux/libreoffice-langpack-espkg:rpm/almalinux/libreoffice-langpack-etpkg:rpm/almalinux/libreoffice-langpack-eupkg:rpm/almalinux/libreoffice-langpack-fapkg:rpm/almalinux/libreoffice-langpack-fipkg:rpm/almalinux/libreoffice-langpack-frpkg:rpm/almalinux/libreoffice-langpack-gapkg:rpm/almalinux/libreoffice-langpack-glpkg:rpm/almalinux/libreoffice-langpack-gupkg:rpm/almalinux/libreoffice-langpack-hepkg:rpm/almalinux/libreoffice-langpack-hipkg:rpm/almalinux/libreoffice-langpack-hrpkg:rpm/almalinux/libreoffice-langpack-hupkg:rpm/almalinux/libreoffice-langpack-idpkg:rpm/almalinux/libreoffice-langpack-itpkg:rpm/almalinux/libreoffice-langpack-japkg:rpm/almalinux/libreoffice-langpack-kkpkg:rpm/almalinux/libreoffice-langpack-knpkg:rpm/almalinux/libreoffice-langpack-kopkg:rpm/almalinux/libreoffice-langpack-ltpkg:rpm/almalinux/libreoffice-langpack-lvpkg:rpm/almalinux/libreoffice-langpack-maipkg:rpm/almalinux/libreoffice-langpack-mlpkg:rpm/almalinux/libreoffice-langpack-mrpkg:rpm/almalinux/libreoffice-langpack-nbpkg:rpm/almalinux/libreoffice-langpack-nlpkg:rpm/almalinux/libreoffice-langpack-nnpkg:rpm/almalinux/libreoffice-langpack-nrpkg:rpm/almalinux/libreoffice-langpack-nsopkg:rpm/almalinux/libreoffice-langpack-orpkg:rpm/almalinux/libreoffice-langpack-papkg:rpm/almalinux/libreoffice-langpack-plpkg:rpm/almalinux/libreoffice-langpack-pt-BRpkg:rpm/almalinux/libreoffice-langpack-pt-PTpkg:rpm/almalinux/libreoffice-langpack-ropkg:rpm/almalinux/libreoffice-langpack-rupkg:rpm/almalinux/libreoffice-langpack-sipkg:rpm/almalinux/libreoffice-langpack-skpkg:rpm/almalinux/libreoffice-langpack-slpkg:rpm/almalinux/libreoffice-langpack-srpkg:rpm/almalinux/libreoffice-langpack-sspkg:rpm/almalinux/libreoffice-langpack-stpkg:rpm/almalinux/libreoffice-langpack-svpkg:rpm/almalinux/libreoffice-langpack-tapkg:rpm/almalinux/libreoffice-langpack-tepkg:rpm/almalinux/libreoffice-langpack-thpkg:rpm/almalinux/libreoffice-langpack-tnpkg:rpm/almalinux/libreoffice-langpack-trpkg:rpm/almalinux/libreoffice-langpack-tspkg:rpm/almalinux/libreoffice-langpack-ukpkg:rpm/almalinux/libreoffice-langpack-vepkg:rpm/almalinux/libreoffice-langpack-xhpkg:rpm/almalinux/libreoffice-langpack-zh-Hanspkg:rpm/almalinux/libreoffice-langpack-zh-Hantpkg:rpm/almalinux/libreoffice-langpack-zupkg:rpm/almalinux/libreoffice-mathpkg:rpm/almalinux/libreoffice-ogltranspkg:rpm/almalinux/libreoffice-opensymbol-fontspkg:rpm/almalinux/libreoffice-pdfimportpkg:rpm/almalinux/libreoffice-pyunopkg:rpm/almalinux/libreoffice-sdkpkg:rpm/almalinux/libreoffice-sdk-docpkg:rpm/almalinux/libreoffice-urepkg:rpm/almalinux/libreoffice-ure-commonpkg:rpm/almalinux/libreoffice-wiki-publisherpkg:rpm/almalinux/libreoffice-writerpkg:rpm/almalinux/libreoffice-x11pkg:rpm/almalinux/libreoffice-xsltfilter
< 1:6.4.7.2-10.el8.alma+ 170 more
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- (no CPE)range: < 1:6.4.7.2-10.el8.alma
- Range: 7-0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.debian.org/security/2021/dsa-4988mitrevendor-advisoryx_refsource_DEBIAN
- www.libreoffice.org/about-us/security/advisories/CVE-2021-25633mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.