Files
CVEs-PoC/2025/CVE-2025-2866.md
T
2025-09-29 21:09:30 +02:00

986 B

CVE-2025-2866

Description

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation.In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as validThis issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.

POC

Reference

No PoCs from references.

Github