Improper Verification of Cryptographic Signature in LibreOffice
CVE-2025-2866

2.4LOW

Key Information:

Vendor
CVE Published:
27 April 2025

What is CVE-2025-2866?

A vulnerability in LibreOffice allows PDF Signature Spoofing due to improper verification of cryptographic signatures. Specifically, flaws in the verification code for adbe.pkcs7.sha1 signatures may result in invalid signatures being mistakenly accepted as valid. This issue impacts users of LibreOffice versions 24.8 (before 24.8.6) and 25.2 (before 25.2.2), posing a risk to the integrity of signed PDF documents.

Affected Version(s)

LibreOffice 24.8

LibreOffice 25.2

References

CVSS V4

Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks to Juraj Ĺ arinay for discovering this issue and for providing a fix
.