#3 Timestamp Manipulation with Signature Wrapping
Fixed in Apache OpenOffice 4.1.11
It is possible for an attacker to manipulate the timestamp of signed documents.
An attacker can use the vulnerability to convert an untrusted digital signature into trusted ones and allows the time stamp of the signature to be changed arbitrarily.
There are no known exploits of this vulnerability.
A proof-of-concept demonstration exists.
Thanks to the reporter for discovering this issue.
Vendor: The Apache Software Foundation
All Apache OpenOffice versions 4.1.10 and older are affected.
OpenOffice.org versions may also be affected.
Install Apache OpenOffice 4.1.11 for the latest maintenance and cumulative security fixes. Use the Apache OpenOffice download page.
The Apache OpenOffice Security Team would like to thank Simon Rohlmann, Vladislav Mladenov, Christian Mainka and Jörg Schwenk, Ruhr University Bochum, Germany, for discovering and reporting this attack vector.
This issue was also reported to LibreOffice with CVE-2021-25634.
The latest information on Apache OpenOffice security bulletins can be found at the Bulletin Archive page.