CVE Vulnerabilities

CVE-2024-6472

Improper Certificate Validation

Published: Aug 05, 2024 | Modified: Aug 06, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

Certificate Validation user interface in LibreOffice allows potential vulnerability.

Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. When a document with a signed macro is opened a warning is displayed by LibreOffice before the macro is executed.

Previously if verification failed the user could fail to understand the failure and choose to enable the macros anyway.

This issue affects LibreOffice: from 24.2 before 24.2.5.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 8 RedHat libreoffice-1:6.4.7.2-18.el8_10 *
Red Hat Enterprise Linux 8.2 Advanced Update Support RedHat libreoffice-1:6.0.6.1-22.el8_2 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat libreoffice-1:6.4.7.2-17.el8_4 *
Red Hat Enterprise Linux 8.4 Telecommunications Update Service RedHat libreoffice-1:6.4.7.2-17.el8_4 *
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions RedHat libreoffice-1:6.4.7.2-17.el8_4 *
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support RedHat libreoffice-1:6.4.7.2-17.el8_6 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat libreoffice-1:6.4.7.2-17.el8_6 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat libreoffice-1:6.4.7.2-17.el8_6 *
Red Hat Enterprise Linux 8.8 Extended Update Support RedHat libreoffice-1:6.4.7.2-17.el8_8 *
Red Hat Enterprise Linux 9 RedHat libreoffice-1:7.1.8.1-14.el9_4 *
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions RedHat libreoffice-1:7.1.8.1-13.el9_0 *
Red Hat Enterprise Linux 9.2 Extended Update Support RedHat libreoffice-1:7.1.8.1-13.el9_2 *
Libreoffice Ubuntu devel *
Libreoffice Ubuntu focal *
Libreoffice Ubuntu jammy *
Libreoffice Ubuntu noble *
Libreoffice Ubuntu upstream *

Potential Mitigations

References