Signatures in "repair mode" should not be trusted
CVE-2024-7788

7.8HIGH

Key Information:

Vendor
CVE Published:
17 September 2024

What is CVE-2024-7788?

An improper digital signature invalidation vulnerability in the Zip Repair Mode of LibreOffice allows for signature forgery. This affects versions of LibreOffice from 24.2 to those prior to 24.2.5, potentially enabling unauthorized actions through falsified document signatures.

Affected Version(s)

LibreOffice 24.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Credit

Thanks to Thanks to Yufan You for finding and reporting this issue
Thanks to Michael Stahl of allotropia for providing a fix
.