Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal.
An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files.
This issue affects LibreOffice: from 24.8 before < 24.8.4.
Metrics
Affected Vendors & Products
References
History
Thu, 09 Jan 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Tue, 07 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 07 Jan 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4. | |
Title | Path traversal leading to arbitrary .ttf file write | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: Document Fdn.
Published: 2025-01-07T11:15:08.251Z
Updated: 2025-01-07T14:17:01.599Z
Reserved: 2024-12-10T16:37:20.903Z
Link: CVE-2024-12425
Vulnrichment
Updated: 2025-01-07T14:16:58.024Z
NVD
Status : Received
Published: 2025-01-07T12:15:24.183
Modified: 2025-01-07T12:15:24.183
Link: CVE-2024-12425
Redhat