First published: Tue Sep 17 2024(Updated: )
Improper Digital Signature Invalidation vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerability in LibreOfficeThis issue affects LibreOffice: from 24.2 before < 24.2.5.
Credit: security@documentfoundation.org security@documentfoundation.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libreoffice | <=1:7.0.4-4+deb11u10<=4:7.4.7-1+deb12u4 | 4:7.4.7-1+deb12u5 4:24.2.5-4 4:24.2.6-2 |
LibreOffice Draw | >=24.2.0<24.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7788 is classified as a moderate severity vulnerability due to the potential for signature forgery.
To fix CVE-2024-7788, upgrade LibreOffice to versions 24.2.5 or later.
CVE-2024-7788 affects LibreOffice versions from 24.2.0 to prior than 24.2.5.
CVE-2024-7788 allows for possible signature forgery, compromising the integrity of documents.
The recommended approach for CVE-2024-7788 is to upgrade to a protected version rather than relying on a workaround.