USN-7228-1: LibreOffice vulnerabilities
Thomas Rinsma discovered that LibreOffice incorrectly handled paths when processing embedded font files. If a user or automated system were tricked into opening a specially crafted LibreOffice file, a remote attacker could possibly use this issue to create arbitrary files ending with ".ttf". (CVE-2024-12425) Thomas Rinsma discovered that LibreOffice incorrectly handled certain environment variables and INI file values. If a user or automated system were tricked into opening a specially crafted LibreOffice file, a remote attacker could possibly use this issue to exfiltrate sensitive information. (CVE-2024-12426)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7228-1?
USN-7228-1 is classified as a high-severity vulnerability due to the potential for arbitrary file creation by remote attackers.
How do I fix USN-7228-1?
To fix USN-7228-1, upgrade LibreOffice to the remedied versions provided for your Ubuntu release.
What does USN-7228-1 affect?
USN-7228-1 affects multiple versions of LibreOffice packaged for Ubuntu, including 20.04, 22.04, and 24.04.
What are the risks of not addressing USN-7228-1?
Not addressing USN-7228-1 may allow attackers to exploit the vulnerability, potentially leading to unauthorized file creation.
Who discovered USN-7228-1?
USN-7228-1 was discovered by Thomas Rinsma who found issues with how LibreOffice handles embedded font file paths.