Description
Improper Digital Signature Invalidation vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerability in LibreOfficeThis issue affects LibreOffice: from 24.2 before < 24.2.5.
Problem types
CWE-347 Improper Verification of Cryptographic Signature
Product status
24.2 (24.2 series) before < 24.2.5
Credits
Thanks to Thanks to Yufan You for finding and reporting this issue
Thanks to Michael Stahl of allotropia for providing a fix
References
lists.debian.org/debian-lts-announce/2024/10/msg00007.html
www.libreoffice.org/...-us/security/advisories/CVE-2024-7788