First published: Tue Jan 07 2025(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4.
Credit: security@documentfoundation.org security@documentfoundation.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libreoffice | <=1:7.0.4-4+deb11u10<=4:7.4.7-1+deb12u5 | 1:7.0.4-4+deb11u12 4:7.4.7-1+deb12u6 4:24.8.4-1 4:24.8.4-2 |
LibreOffice Draw | >24.8<24.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12425 has a high severity rating due to its ability to allow path traversal attacks that can lead to unauthorized file access.
To fix CVE-2024-12425, upgrade LibreOffice to version 24.8.4 or later, or apply relevant patches provided by your distribution.
CVE-2024-12425 affects LibreOffice versions prior to 24.8.4, including certain Debian and Ubuntu package versions.
Yes, CVE-2024-12425 can potentially be exploited remotely by an attacker sending crafted files to the affected version of LibreOffice.
CVE-2024-12425 can facilitate arbitrary file writes due to improper path restrictions, which may lead to data corruption or unauthorized data access.