CVE-2021-25636


Incorrect trust validation of signature with ambiguous KeyInfo children

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.



We have discovered 53 live websites that are affected by CVE-2021-25636.

Contact us to get more info




Affected Software

Product  LibreOffice
Category Content Management System
Vulnerable Versions
  • from 7.2 before 7.2.5
Total Vulnerable Versions195
Vulnerable Domains53 live websites (1.57% of LibreOffice install base)


Common Weakness Enumeration


CWE-347 Improper Verification of Cryptographic Signature



Details

  • Published - Feb 22, 2022
  • Updated - Mar 26, 2023

Credits

  • Thanks to NDS of Ruhr University Bochum for discovering and reporting this problem.





Countries

United States14 websites



Germany15 websites
France6 websites
China3 websites
Czech Republic2 websites
GB2 websites
Hungary2 websites
Netherlands2 websites
Canada1 websites

TLDs

.com13 websites
.de11 websites
.org5 websites
.fr5 websites
.cn2 websites
.cz2 websites
.net2 websites
.nl2 websites
.ca1 websites
.ch1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2021-25636

Top websites that are affected by CVE-2021-25636. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.***.cn China*,***,***
******.*********.de Germany*,***,***
***.*******.com United States*,***,***
***.***.cn China*,***,***
****.org United States*,***,***
****************.de Germany*,***,***
****.net United States*,***,***
**********.de Germany*,***,***
*********.com United States*,***,***
***************.***.nl Netherlands**,***,***
See full domain list