CVE-2024-12425
07.01.2025, 12:15
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal.
An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files.
This issue affects LibreOffice: from 24.8 before < 24.8.4.| Vendor | Product | Version |
|---|---|---|
| libreoffice | libreoffice | 24.8.0.1 ≤ 𝑥 < 24.8.4 |
| libreoffice | libreoffice | 24.8.0.0:alpha1 |
| libreoffice | libreoffice | 24.8.0.0:beta1 |
| debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases