{"id":"CVE-2025-2866","details":"Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation.\n\n\n\n\nIn the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid\n\n\n\n\nThis issue affects LibreOffice: from 24.8 before \u003c 24.8.6, from 25.2 before \u003c 25.2.2.","modified":"2026-07-07T08:53:33.403905566Z","published":"2025-04-27T19:15:15.137Z","database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","vendor_product":"libreoffice:libreoffice","cpes":["cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"24.8.0.1"},{"fixed":"24.8.6.0"},{"introduced":"25.2.0.1"},{"fixed":"25.2.2"}]}]},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/06/msg00002.html"},{"type":"ADVISORY","url":"https://www.libreoffice.org/about-us/security/advisories/cve-2025-2866"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libreoffice/core","events":[{"introduced":"a17e39caaf73108bee692d6f64a44c62f4066f1d"},{"last_affected":"5a5fc103cad77dc243b7e54511502054c12c121c"}],"database_specific":{"extracted_events":[{"introduced":"24.8.0.0-alpha1"},{"last_affected":"24.8.0.0-alpha1"},{"introduced":"24.8.0.0-beta1"},{"last_affected":"24.8.0.0-beta1"},{"introduced":"25.2.0.0-alpha1"},{"last_affected":"25.2.0.0-alpha1"},{"introduced":"25.2.0.0-beta1"},{"last_affected":"25.2.0.0-beta1"}],"source":"CPE_STRING","cpe":["cpe:2.3:a:libreoffice:libreoffice:24.8.0.0:alpha1:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice:24.8.0.0:beta1:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice:25.2.0.0:alpha1:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice:25.2.0.0:beta1:*:*:*:*:*:*"]}}],"versions":["24.8.0.0-alpha1","24.8.0.0-beta1","25.2.0.0-alpha1","25.2.0.0-beta1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-2866.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"}]}