First published: Sun Apr 27 2025(Updated: )
Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.
Credit: security@documentfoundation.org
Affected Software | Affected Version | How to fix |
---|---|---|
>=24.8<24.8.6 | ||
>=25.2<25.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2866 is classified as a high-severity vulnerability due to its potential to allow PDF signature spoofing.
To mitigate CVE-2025-2866, users should update LibreOffice to a version that is not affected, i.e., beyond 24.8.6 or 25.2.2.
LibreOffice versions from 24.8 to 24.8.6 and 25.2 to 25.2.2 are affected by CVE-2025-2866.
CVE-2025-2866 could allow attackers to spoof PDF signatures, misleading users into trusting invalid documents.
Yes, CVE-2025-2866 involves improper verification of cryptographic signatures, specifically for adbe.pkcs7.sha1 signatures.