Improper Verification of Cryptographic Signature in LibreOffice
CVE-2025-2866
2.4LOW
What is CVE-2025-2866?
A vulnerability in LibreOffice allows PDF Signature Spoofing due to improper verification of cryptographic signatures. Specifically, flaws in the verification code for adbe.pkcs7.sha1 signatures may result in invalid signatures being mistakenly accepted as valid. This issue impacts users of LibreOffice versions 24.8 (before 24.8.6) and 25.2 (before 25.2.2), posing a risk to the integrity of signed PDF documents.
Affected Version(s)
LibreOffice 24.8
LibreOffice 25.2
References
CVSS V4
Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks to Juraj Ĺ arinay for discovering this issue and for providing a fix
