vulnerability

SUSE: CVE-2022-26305: SUSE Linux Security Advisory

Severity
8
CVSS
(AV:N/AC:H/Au:N/C:C/I:C/A:C)
Published
2022-07-25
Added
2022-10-26
Modified
2025-01-28

Description

An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only matching the serial number and issuer string of the used certificate with that of a trusted certificate. This is not sufficient to verify that the macro was actually signed with the certificate. An adversary could therefore create an arbitrary certificate with a serial number and an issuer string identical to a trusted certificate which LibreOffice would present as belonging to the trusted author, potentially leading to the user to execute arbitrary code contained in macros improperly trusted. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.1.

Solution(s)

suse-upgrade-libreofficesuse-upgrade-libreoffice-basesuse-upgrade-libreoffice-base-drivers-postgresqlsuse-upgrade-libreoffice-branding-upstreamsuse-upgrade-libreoffice-calcsuse-upgrade-libreoffice-calc-extensionssuse-upgrade-libreoffice-drawsuse-upgrade-libreoffice-filters-optionalsuse-upgrade-libreoffice-gdb-pretty-printerssuse-upgrade-libreoffice-gladesuse-upgrade-libreoffice-gnomesuse-upgrade-libreoffice-gtk3suse-upgrade-libreoffice-icon-themessuse-upgrade-libreoffice-impresssuse-upgrade-libreoffice-l10n-afsuse-upgrade-libreoffice-l10n-amsuse-upgrade-libreoffice-l10n-arsuse-upgrade-libreoffice-l10n-assuse-upgrade-libreoffice-l10n-astsuse-upgrade-libreoffice-l10n-besuse-upgrade-libreoffice-l10n-bgsuse-upgrade-libreoffice-l10n-bnsuse-upgrade-libreoffice-l10n-bn_insuse-upgrade-libreoffice-l10n-bosuse-upgrade-libreoffice-l10n-brsuse-upgrade-libreoffice-l10n-brxsuse-upgrade-libreoffice-l10n-bssuse-upgrade-libreoffice-l10n-casuse-upgrade-libreoffice-l10n-ca_valenciasuse-upgrade-libreoffice-l10n-ckbsuse-upgrade-libreoffice-l10n-cssuse-upgrade-libreoffice-l10n-cysuse-upgrade-libreoffice-l10n-dasuse-upgrade-libreoffice-l10n-desuse-upgrade-libreoffice-l10n-dgosuse-upgrade-libreoffice-l10n-dsbsuse-upgrade-libreoffice-l10n-dzsuse-upgrade-libreoffice-l10n-elsuse-upgrade-libreoffice-l10n-ensuse-upgrade-libreoffice-l10n-en_gbsuse-upgrade-libreoffice-l10n-en_zasuse-upgrade-libreoffice-l10n-eosuse-upgrade-libreoffice-l10n-essuse-upgrade-libreoffice-l10n-etsuse-upgrade-libreoffice-l10n-eususe-upgrade-libreoffice-l10n-fasuse-upgrade-libreoffice-l10n-fisuse-upgrade-libreoffice-l10n-frsuse-upgrade-libreoffice-l10n-fursuse-upgrade-libreoffice-l10n-fysuse-upgrade-libreoffice-l10n-gasuse-upgrade-libreoffice-l10n-gdsuse-upgrade-libreoffice-l10n-glsuse-upgrade-libreoffice-l10n-gususe-upgrade-libreoffice-l10n-gugsuse-upgrade-libreoffice-l10n-hesuse-upgrade-libreoffice-l10n-hisuse-upgrade-libreoffice-l10n-hrsuse-upgrade-libreoffice-l10n-hsbsuse-upgrade-libreoffice-l10n-hususe-upgrade-libreoffice-l10n-idsuse-upgrade-libreoffice-l10n-issuse-upgrade-libreoffice-l10n-itsuse-upgrade-libreoffice-l10n-jasuse-upgrade-libreoffice-l10n-kasuse-upgrade-libreoffice-l10n-kabsuse-upgrade-libreoffice-l10n-kksuse-upgrade-libreoffice-l10n-kmsuse-upgrade-libreoffice-l10n-kmr_latnsuse-upgrade-libreoffice-l10n-knsuse-upgrade-libreoffice-l10n-kosuse-upgrade-libreoffice-l10n-koksuse-upgrade-libreoffice-l10n-kssuse-upgrade-libreoffice-l10n-lbsuse-upgrade-libreoffice-l10n-losuse-upgrade-libreoffice-l10n-ltsuse-upgrade-libreoffice-l10n-lvsuse-upgrade-libreoffice-l10n-maisuse-upgrade-libreoffice-l10n-mksuse-upgrade-libreoffice-l10n-mlsuse-upgrade-libreoffice-l10n-mnsuse-upgrade-libreoffice-l10n-mnisuse-upgrade-libreoffice-l10n-mrsuse-upgrade-libreoffice-l10n-mysuse-upgrade-libreoffice-l10n-nbsuse-upgrade-libreoffice-l10n-nesuse-upgrade-libreoffice-l10n-nlsuse-upgrade-libreoffice-l10n-nnsuse-upgrade-libreoffice-l10n-nrsuse-upgrade-libreoffice-l10n-nsosuse-upgrade-libreoffice-l10n-ocsuse-upgrade-libreoffice-l10n-omsuse-upgrade-libreoffice-l10n-orsuse-upgrade-libreoffice-l10n-pasuse-upgrade-libreoffice-l10n-plsuse-upgrade-libreoffice-l10n-pt_brsuse-upgrade-libreoffice-l10n-pt_ptsuse-upgrade-libreoffice-l10n-rosuse-upgrade-libreoffice-l10n-rususe-upgrade-libreoffice-l10n-rwsuse-upgrade-libreoffice-l10n-sa_insuse-upgrade-libreoffice-l10n-satsuse-upgrade-libreoffice-l10n-sdsuse-upgrade-libreoffice-l10n-sisuse-upgrade-libreoffice-l10n-sidsuse-upgrade-libreoffice-l10n-sksuse-upgrade-libreoffice-l10n-slsuse-upgrade-libreoffice-l10n-sqsuse-upgrade-libreoffice-l10n-srsuse-upgrade-libreoffice-l10n-sssuse-upgrade-libreoffice-l10n-stsuse-upgrade-libreoffice-l10n-svsuse-upgrade-libreoffice-l10n-sw_tzsuse-upgrade-libreoffice-l10n-szlsuse-upgrade-libreoffice-l10n-tasuse-upgrade-libreoffice-l10n-tesuse-upgrade-libreoffice-l10n-tgsuse-upgrade-libreoffice-l10n-thsuse-upgrade-libreoffice-l10n-tnsuse-upgrade-libreoffice-l10n-trsuse-upgrade-libreoffice-l10n-tssuse-upgrade-libreoffice-l10n-ttsuse-upgrade-libreoffice-l10n-ugsuse-upgrade-libreoffice-l10n-uksuse-upgrade-libreoffice-l10n-uzsuse-upgrade-libreoffice-l10n-vesuse-upgrade-libreoffice-l10n-vecsuse-upgrade-libreoffice-l10n-visuse-upgrade-libreoffice-l10n-xhsuse-upgrade-libreoffice-l10n-zh_cnsuse-upgrade-libreoffice-l10n-zh_twsuse-upgrade-libreoffice-l10n-zususe-upgrade-libreoffice-librelogosuse-upgrade-libreoffice-mailmergesuse-upgrade-libreoffice-mathsuse-upgrade-libreoffice-officebeansuse-upgrade-libreoffice-pyunosuse-upgrade-libreoffice-qt5suse-upgrade-libreoffice-sdksuse-upgrade-libreoffice-sdk-docsuse-upgrade-libreoffice-writersuse-upgrade-libreoffice-writer-extensionssuse-upgrade-libreofficekitsuse-upgrade-libreofficekit-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.