First published: Thu May 08 2025(Updated: )
Juraj Šarinay discovered that LibreOffice incorrectly handled verifying PDF signatures. A remote attacker could possibly use this issue to generate PDF files that appear to have a valid signature.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libreoffice | <4:24.8.6-0ubuntu0.24.10.2 | 4:24.8.6-0ubuntu0.24.10.2 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/libreoffice | <4:24.2.7-0ubuntu0.24.04.4 | 4:24.2.7-0ubuntu0.24.04.4 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/libreoffice | <1:7.3.7-0ubuntu0.22.04.10 | 1:7.3.7-0ubuntu0.22.04.10 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libreoffice | <1:6.4.7-0ubuntu0.20.04.15 | 1:6.4.7-0ubuntu0.20.04.15 |
Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-7504-1 is critical due to the potential for remote attackers to forge PDF signatures.
To fix USN-7504-1, update LibreOffice to the latest version specified in the advisory for your Ubuntu version.
USN-7504-1 affects multiple versions of LibreOffice across various Ubuntu releases including 24.10, 24.04, 22.04, and 20.04.
Yes, USN-7504-1 can be exploited remotely as the vulnerability allows attackers to create malicious PDF files with forged signatures.
If you cannot update LibreOffice, avoid opening untrusted PDF files until the issue is resolved.