Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6x53-588x-53g2

Опубликовано: 07 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2.4
CVSS3: 3.3

Описание

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal.

An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files.

This issue affects LibreOffice: from 24.8 before < 24.8.4.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal.

An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files.

This issue affects LibreOffice: from 24.8 before < 24.8.4.

EPSS

Процентиль: 44%
0.00221
Низкий

2.4 Low

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 1 года назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4.

CVSS3: 2.8
redhat
около 1 года назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4.

CVSS3: 3.3
nvd
около 1 года назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4.

CVSS3: 3.3
debian
около 1 года назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...

CVSS3: 3.3
fstec
около 1 года назад

Уязвимость пакета офисных программ LibreOffice, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных

EPSS

Процентиль: 44%
0.00221
Низкий

2.4 Low

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-22