Alpine: multiple libreoffice packages: security update to 7.2.5.2-r0

high Tenable Self-Hosted Container Security Plugin ID 405261

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual
aids that no alteration of the document occurred since the last signing and that the signature is valid.
An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally
signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the
document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused
LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value.
This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5. (CVE-2021-25636)

See Also

https://security.alpinelinux.org/vuln/CVE-2021-25636

Plugin Details

Severity: High

ID: 405261

Version: Revision 1.31

Type: Local

Published: 10/31/2023

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2021-25636

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 2/22/2022

Reference Information

CVE: CVE-2021-25636