USN-7025-1: LibreOffice vulnerability
Published Sep 19, 2024
·Updated
It was discovered that LibreOffice would incorrectly handle digital signature verification after repairing a corrupted document. A remote attacker could possibly use this issue to forge valid signatures.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/libreoffice<1:7.3.7-0ubuntu0.22.04.7
1:7.3.7-0ubuntu0.22.04.7
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libreoffice<1:6.4.7-0ubuntu0.20.04.12
1:6.4.7-0ubuntu0.20.04.12
Ubuntu Ubuntu=20.04
Event History
Sep 19, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7025-1?
The severity of USN-7025-1 is considered important due to the potential for digital signature forgery.
2
How do I fix USN-7025-1?
To fix USN-7025-1, update LibreOffice to the latest version available for your Ubuntu release.
3
Who is affected by USN-7025-1?
Users running LibreOffice on Ubuntu 20.04 or Ubuntu 22.04 are affected by USN-7025-1.
4
What can an attacker do due to USN-7025-1?
An attacker could exploit USN-7025-1 to forge valid digital signatures on documents repaired by LibreOffice.
5
What versions of LibreOffice are impacted by USN-7025-1?
LibreOffice versions 1:6.4.7-0ubuntu0.20.04.12 and 1:7.3.7-0ubuntu0.22.04.7 are impacted by USN-7025-1.