Improper Certificate Validation Affecting libreoffice package, versions [,7.2.7)[7.3.0,7.3.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.23% (62nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-LIBREOFFICE-2960425
  • published27 Jul 2022
  • disclosed26 Jul 2022
  • creditOpenSource Security Gmb

Introduced: 26 Jul 2022

CVE-2022-26305  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

Upgrade libreoffice to version 7.2.7, 7.3.1 or higher.

Overview

Affected versions of this package are vulnerable to Improper Certificate Validation due insufficient validation of signing author of a macro.

An attacker could create an arbitrary certificate with a serial number and an issuer string identical to ones of a trusted certificate, potentially leading to the user to execute arbitrary code.

CVSS Scores

version 3.1