It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25634 for the LibreOffice advisory.
References
Configurations
History
21 Nov 2024, 06:26
Type | Values Removed | Values Added |
---|---|---|
References | () https://lists.apache.org/thread.html/ra74d5057cdc781a36286a83e8bcbc90a7678f030ae73339c35dfc4f9%40%3Cusers.openoffice.apache.org%3E - Mailing List, Vendor Advisory | |
References | () https://lists.apache.org/thread.html/rc5c277cb83e335696657c5f27da1d1e2b5cb48346b0b55415a233757%40%3Cannounce.apache.org%3E - |
19 Oct 2021, 17:54
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-347 | |
CPE | cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 5.3 |
References | (CONFIRM) https://lists.apache.org/thread.html/ra74d5057cdc781a36286a83e8bcbc90a7678f030ae73339c35dfc4f9%40%3Cusers.openoffice.apache.org%3E - Mailing List, Vendor Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/rc5c277cb83e335696657c5f27da1d1e2b5cb48346b0b55415a233757@%3Cannounce.apache.org%3E - Mailing List, Vendor Advisory |
11 Oct 2021, 12:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
11 Oct 2021, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-10-11 08:15
Updated : 2024-11-21 06:26
NVD link : CVE-2021-41831
Mitre link : CVE-2021-41831
CVE.ORG link : CVE-2021-41831
JSON object : View
Products Affected
apache
- openoffice
CWE
CWE-347
Improper Verification of Cryptographic Signature