#1 Content Manipulation with Certificate Double Attack
#2 Macro Manipulation with Certificate Double Attack
Fixed in Apache OpenOffice 4.1.11
It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source.
An attacker can use the vulnerabilities to convert an untrusted digital signature into trusted ones and change the content of the ODF document without invalidating the signature.
There are no known exploits of this vulnerability.
A proof-of-concept demonstration exists.
Thanks to the reporter for discovering this issue.
Vendor: The Apache Software Foundation
All Apache OpenOffice versions 4.1.10 and older are affected.
OpenOffice.org versions may also be affected.
Install Apache OpenOffice 4.1.11 for the latest maintenance and cumulative security fixes. Use the Apache OpenOffice download page.
The Apache OpenOffice Security Team would like to thank Simon Rohlmann, Vladislav Mladenov, Christian Mainka and Jörg Schwenk, Ruhr University Bochum, Germany, for discovering and reporting this attack vector.
This issue was also reported to LibreOffice with CVE-2021-25633.
The latest information on Apache OpenOffice security bulletins can be found at the Bulletin Archive page.