Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian LTS: DLA-4205-1 moderate: libreoffice PDF signature spoofing

debian lts
Calendar Grey June 1, 2025
Dist Debian Esm H88
Various bugs resolved in LibreOffice concerning web browser functions and unauthorized PDF signature manipulation for Debian system users.
Multiple vulnerabilities were discovered in Libreoffice, an office productivity software suite

Summary

CVE-2025-1080

LibreOffice supports Office URI Schemes to enable browser
integration of LibreOffice with MS SharePoint server. An additional
scheme 'vnd.libreoffice.command' specific to LibreOffice was added.
In the affected versions of LibreOffice a link in a browser using
that scheme could be constructed with an embedded inner URL that
when passed to LibreOffice could call internal macros with arbitrary
arguments.

CVE-2025-2866

LibreOffice allows PDF Signature Spoofing by Improper Validation. In
the affected versions of LibreOffice a flaw in the verification code
for adbe.pkcs7.sha1 signatures could cause invalid signatures to be
accepted as valid

For Debian 11 bullseye, these problems have been fixed in version
1:7.0.4-4+deb11u13.

We recommend that you upgrade your libreoffice packages.

For the detailed security status of libreoffice please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libreoffice

Read the Full Advisory


Package: libreoffice
Version: 1:7.0.4-4+deb11u13
CVE ID: CVE-2025-1080 CVE-2025-2866

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here