
=====================================================================

                             CERT-Renater

                 Note d'Information No. 2021/VULN540
_____________________________________________________________________

DATE                : 18/10/2021

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running LibreOffice versions prior to
                                        7.0.6, 7.1.2.

=====================================================================
https://www.libreoffice.org/about-us/security/advisories/cve-2021-25632/
https://www.libreoffice.org/about-us/security/advisories/cve-2021-25633/
https://www.libreoffice.org/about-us/security/advisories/cve-2021-25634/
_____________________________________________________________________


CVE-2021-25633

Title: Content Manipulation with Double Certificate Attack

Announced: October 11, 2021

Fixed in: LibreOffice 7.0.6/7.1.2


Description:

LibreOffice supports digital signatures of ODF documents and macros
within documents, presenting visual aids that no alteration of the
document occurred since the last signing and that the signature is
valid.

An Improper Certificate Validation vulnerability in LibreOffice allowed
an attacker to create a digitally signed ODF document, by manipulating
the documentsignatures.xml or macrosignatures.xml stream within the
document to combine multiple certificate data, which when opened caused
LibreOffice to display a validly signed indicator but whose content was
unrelated to the signature shown.


References:

NDS of Ruhr University Bochum for discovering and reporting this
problem.

Thanks to Michael Stahl of allotropia software GmbH for solving this
problem.


References:

    CVE-2021-25633

_____________________________________________________________________

CVE-2021-25633

Title: Content Manipulation with Double Certificate Attack

Announced: October 11, 2021

Fixed in: LibreOffice 7.0.6/7.1.2


Description:

LibreOffice supports digital signatures of ODF documents and macros
within documents, presenting visual aids that no alteration of the
document occurred since the last signing and that the signature is
valid.

An Improper Certificate Validation vulnerability in LibreOffice allowed
an attacker to create a digitally signed ODF document, by manipulating
the documentsignatures.xml or macrosignatures.xml stream within the
document to combine multiple certificate data, which when opened caused
LibreOffice to display a validly signed indicator but whose content was
unrelated to the signature shown.


References:

NDS of Ruhr University Bochum for discovering and reporting this
problem.

Thanks to Michael Stahl of allotropia software GmbH for solving this
problem.


References:

    CVE-2021-25633

_____________________________________________________________________

CVE-2021-25634

Title: Timestamp Manipulation with Signature Wrapping

Announced: October 11, 2021

Fixed in: LibreOffice 7.0.6/7.1.2


Description:

LibreOffice supports digital signatures of ODF documents and macros
within documents, presenting visual aids that no alteration of the
document occurred since the last signing and that the signature is
valid.

An Improper Certificate Validation vulnerability in LibreOffice allowed
an attacker to modify a digitally signed ODF document to insert an
additional signing time timestamp which LibreOffice would incorrectly
present as a valid signature signed at the bogus signing time.


References:

Thanks to NDS of Ruhr University Bochum for discovering and reporting
this problem.

Thanks to Michael Stahl of allotropia software GmbH for solving this
problem.


References:

    CVE-2021-25634

=========================================================
+ CERT-RENATER       |    tel : 01-53-94-20-44          +
+ 23/25 Rue Daviel   |    fax : 01-53-94-20-41          +
+ 75013 Paris        |    email:cert@support.renater.fr +
=========================================================


