It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25634 for the LibreOffice advisory.
References
Link | Resource |
---|---|
https://lists.apache.org/thread.html/ra74d5057cdc781a36286a83e8bcbc90a7678f030ae73339c35dfc4f9%40%3Cusers.openoffice.apache.org%3E | Mailing List Vendor Advisory |
https://lists.apache.org/thread.html/rc5c277cb83e335696657c5f27da1d1e2b5cb48346b0b55415a233757@%3Cannounce.apache.org%3E | Mailing List Vendor Advisory |
Configurations
Information
Published : 2021-10-11 01:15
Updated : 2021-10-19 10:54
NVD link : CVE-2021-41831
Mitre link : CVE-2021-41831
JSON object : View
CWE
CWE-347
Improper Verification of Cryptographic Signature
Products Affected
apache
- openoffice