QID 376265

Date Published: 2022-02-14

QID 376265: LibreOffice check for Memory corruption via DER-encoded DSA and Rivest-Shamir-Adleman (RSA)-PSS (CVE-2021-43527)

LibreOffice is a office suite application.

CVE-2021-43527 : Memory corruption via DER-encoded DSA and RSA-PSS signatures.

Affected versions:
LibreOffice versions prior to 7.1.8

LibreOffice versions from 7.2.0 prior to 7.2.4

QID Detection Logic (Authenticated):
This QID checks the vulnerable version of LibreOffice by checking the file version of file soffice.exe.

Successful exploitation could allow attacker for Denial of Service(DOS)

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to LibreOffice version 7.1.8/7.2.4 or later. For more information refer LibreOffice
    Vendor References

    CVEs related to QID 376265

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-43527 URL Logo www.libreoffice.org/about-us/security/advisories/