ODF format security: encryption, signatures and metadata management

Open Document Format (ODF) is an open standard for office documents – texts, spreadsheets, presentations and more – that is flexible and interoperable. As with any other digital format, its security is a key concern, as ODF files often contain sensitive information that, without adequate protection measures, can be exposed, tampered with or tracked.

This post analyses how ODF handles security, focusing on encryption, digital signatures and metadata management: three features that protect documents from prying eyes and tampering.…

LibreOffice Security Backgrounder

Today we are announcing the first release of a very important document that describes – in language accessible to everyone, including non-security specialists – the impressive work done by developers and quality assurance specialists in the area of LibreOffice security.

From now on, the LibreOffice Security Backgrounder will be updated on the occasion of each major release of LibreOffice, i.e.…

LibreOffice 7.2.4 Community and LibreOffice 7.1.8 Community available ahead of schedule to provide an important security fix

Berlin, December 6, 2021 – The Document Foundation announces LibreOffice 7.2.4 Community and LibreOffice 7.1.8 Community to provide a key security fix. Releases are immediately available from https://www.libreoffice.org/download/, and all LibreOffice users are recommended to update their installation. Both new version include the fixed NSS 3.73.0 cryptographic library, to solve CVE-2021-43527 (the nss secfix is the only change compared to the previous version).…

LibreOffice 6.3.1 and LibreOffice 6.2.7 announced, focusing on security

Berlin, September 5, 2019 – The Document Foundation announces LibreOffice 6.3.1, the first minor release of the LibreOffice 6.3 family, and LibreOffice 6.2.7, the seventh minor release of the LibreOffice 6.2 family, with many bug fixes and a key security improvement.

LibreOffice 6.3.1 and LibreOffice 6.2.7 consider the presence of any call to a script-like thing as equally hazardous as a macro, and present the user a warning dialog about the document trying to execute a script.…