Improper Verification of Cryptographic Signature Affecting libreoffice package, versions [,8.3.9)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.18% (56th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-LIBREOFFICE-2370811
  • published26 Jan 2022
  • disclosed7 Jan 2021
  • creditUnknown

Introduced: 7 Jan 2021

CVE-2018-18688  (opens in a new tab)
CWE-347  (opens in a new tab)

How to fix?

Upgrade libreoffice to version 8.3.9 or higher.

Overview

Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature. The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates are displayed to the user without any action by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects LibreOffice, Master PDF Editor, Nitro Pro, Nitro Reader, Nuance Power PDF Standard, PDF Editor 6 Pro, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, Perfect PDF 10 Premium, and Perfect PDF Reader.

References

CVSS Scores

version 3.1