CVE Vulnerabilities

CVE-2025-2866

Improper Verification of Cryptographic Signature

Published: Apr 27, 2025 | Modified: May 12, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
2.8 LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Ubuntu
MEDIUM

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation.

In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid

This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Libreoffice Libreoffice 24.8.0.1 (including) 24.8.6.0 (excluding)
Libreoffice Libreoffice 25.2.0.1 (including) 25.2.2 (excluding)
Libreoffice Libreoffice 24.8.0.0-alpha1 (including) 24.8.0.0-alpha1 (including)
Libreoffice Libreoffice 24.8.0.0-beta1 (including) 24.8.0.0-beta1 (including)
Libreoffice Libreoffice 25.2.0.0-alpha1 (including) 25.2.0.0-alpha1 (including)
Libreoffice Libreoffice 25.2.0.0-beta1 (including) 25.2.0.0-beta1 (including)
Libreoffice Ubuntu focal *
Libreoffice Ubuntu jammy *
Libreoffice Ubuntu noble *
Libreoffice Ubuntu oracular *
Libreoffice Ubuntu upstream *

References