QID 376018

Date Published: 2021-11-11

QID 376018: LibreOffice Content Manipulation with Double Certificate Attack Vulnerability

LibreOffice is a office suite application.

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid.

An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to combine multiple certificate data, which when opened caused LibreOffice to display a validly signed indicator but whose content was unrelated to the signature shown.

Affected versions:
LibreOffice versions prior to 7.0.6/7.1.2

QID Detection Logic (Authenticated):
This QID checks the vulnerable version of LibreOffice by checking the file version of file soffice.exe.

Successful exploitation could allow confidentiality and integrity impact

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to upgrade to LibreOffice version 7.0.6/7.1.2 or later. For more information refer LibreOffice

    CVEs related to QID 376018

    Software Advisories
    Advisory ID Software Component Link
    cve-2021-25633 URL Logo www.libreoffice.org/about-us/security/advisories/cve-2021-25633