CVE-2024-12425: Path traversal leading to arbitrary .ttf file write
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12425?
CVE-2024-12425 has a high severity rating due to its ability to allow path traversal attacks that can lead to unauthorized file access.
How do I fix CVE-2024-12425?
To fix CVE-2024-12425, upgrade LibreOffice to version 24.8.4 or later, or apply relevant patches provided by your distribution.
What systems are affected by CVE-2024-12425?
CVE-2024-12425 affects LibreOffice versions prior to 24.8.4, including certain Debian and Ubuntu package versions.
Can CVE-2024-12425 be exploited remotely?
Yes, CVE-2024-12425 can potentially be exploited remotely by an attacker sending crafted files to the affected version of LibreOffice.
What types of attacks can CVE-2024-12425 facilitate?
CVE-2024-12425 can facilitate arbitrary file writes due to improper path restrictions, which may lead to data corruption or unauthorized data access.