CVE-2025-2866: PDF signature forgery with adbe.pkcs7.sha1 SubFilter
Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2866?
CVE-2025-2866 is classified as a high-severity vulnerability due to its potential to allow PDF signature spoofing.
How do I fix CVE-2025-2866?
To mitigate CVE-2025-2866, users should update LibreOffice to a version that is not affected, i.e., beyond 24.8.6 or 25.2.2.
Which versions of LibreOffice are affected by CVE-2025-2866?
LibreOffice versions from 24.8 to 24.8.6 and 25.2 to 25.2.2 are affected by CVE-2025-2866.
What impact does CVE-2025-2866 have on PDF files?
CVE-2025-2866 could allow attackers to spoof PDF signatures, misleading users into trusting invalid documents.
Is CVE-2025-2866 related to cryptographic verification?
Yes, CVE-2025-2866 involves improper verification of cryptographic signatures, specifically for adbe.pkcs7.sha1 signatures.