Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-12425

Опубликовано: 07 янв. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4.

РелизСтатусПримечание
devel

not-affected

4:24.8.4~rc2-0ubuntu1
esm-infra/focal

not-affected

1:6.4.7-0ubuntu0.20.04.13
focal

released

1:6.4.7-0ubuntu0.20.04.13
jammy

released

1:7.3.7-0ubuntu0.22.04.8
noble

released

4:24.2.7-0ubuntu0.24.04.2
oracular

released

4:24.8.4-0ubuntu0.24.10.2
upstream

released

24.8.4

Показывать по

EPSS

Процентиль: 18%
0.00058
Низкий

Связанные уязвимости

CVSS3: 2.8
redhat
6 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4.

nvd
6 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4.

debian
6 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...

github
6 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4.

CVSS3: 3.3
fstec
6 месяцев назад

Уязвимость пакета офисных программ LibreOffice, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных

EPSS

Процентиль: 18%
0.00058
Низкий