Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-12425

Опубликовано: 07 янв. 2025
Источник: redhat
CVSS3: 2.8
EPSS Низкий

Описание

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4.

A flaw was found in LibreOffice. This vulnerability can allow an attacker to write to arbitrary locations on the file system suffixed with ".ttf" via a specially crafted file that supports embedded font files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreofficeNot affected
Red Hat Enterprise Linux 7libreofficeNot affected
Red Hat Enterprise Linux 8libreofficeNot affected
Red Hat Enterprise Linux 9libreofficeNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2336110LibreOffice: Path traversal leading to arbitrary .ttf file write

EPSS

Процентиль: 18%
0.00058
Низкий

2.8 Low

CVSS3

Связанные уязвимости

ubuntu
6 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4.

nvd
6 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4.

debian
6 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...

github
6 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4.

CVSS3: 3.3
fstec
6 месяцев назад

Уязвимость пакета офисных программ LibreOffice, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных

EPSS

Процентиль: 18%
0.00058
Низкий

2.8 Low

CVSS3