Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. When a document with a signed macro is opened a warning is displayed by LibreOffice before the macro is executed. Previously if verification failed the user could fail to understand the failure and choose to enable the macros anyway. This issue affects LibreOffice: from 24.2 before 24.2.5.
History

Thu, 29 Aug 2024 19:00:00 +0000

Type Values Removed Values Added
Metrics threat_severity

Important

threat_severity

Moderate


Tue, 27 Aug 2024 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:rhel_aus:8.2

Wed, 21 Aug 2024 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:rhel_aus:8.4
cpe:/a:redhat:rhel_e4s:8.4
cpe:/a:redhat:rhel_tus:8.4

Tue, 20 Aug 2024 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Eus
Redhat rhel Tus
CPEs cpe:/a:redhat:enterprise_linux:8
cpe:/a:redhat:enterprise_linux:9
cpe:/a:redhat:rhel_aus:8.6
cpe:/a:redhat:rhel_e4s:8.6
cpe:/a:redhat:rhel_e4s:9.0
cpe:/a:redhat:rhel_eus:8.8
cpe:/a:redhat:rhel_eus:9.2
cpe:/a:redhat:rhel_tus:8.6
Vendors & Products Redhat
Redhat enterprise Linux
Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Eus
Redhat rhel Tus

cve-icon MITRE

Status: PUBLISHED

Assigner: Document Fdn.

Published: 2024-08-05T12:55:39.199Z

Updated: 2024-08-05T14:32:48.640Z

Reserved: 2024-07-03T09:26:27.358Z

Link: CVE-2024-6472

cve-icon Vulnrichment

Updated: 2024-08-05T14:30:57.514Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-05T13:15:47.033

Modified: 2024-08-06T16:31:05.780

Link: CVE-2024-6472

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-08-05T00:00:00Z

Links: CVE-2024-6472 - Bugzilla