Path traversal in LibreOffice - CVE-2024-12425

 

Path traversal in LibreOffice - CVE-2024-12425

Published: January 7, 2025


Vulnerability identifier: #VU102416
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-12425
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to overwrite arbitrary files on the system.

The vulnerability exists due to input validation error when processing documents with embedded .ttf font files. A remote attacker can create a specially crafted document, trick the victim into opening and and overwrite arbitrary files on the system, leading to remote code execution.


Affected software

LibreOffice
Debian Linux
Gentoo Linux
Ubuntu
libreoffice (Ubuntu package)
libreoffice (Debian package)
app-office/libreoffice
app-office/libreoffice-bin

How to mitigate CVE-2024-12425

Install update from vendor's website.

LibreOffice - update to 24.8.4.1
libreoffice (Ubuntu package) - addressed in versions 1:6.4.7-0ubuntu0.20.04.13, 1:7.3.7-0ubuntu0.22.04.8, 4:24.2.7-0ubuntu0.24.04.2, 4:24.8.4-0ubuntu0.24.10.2
libreoffice (Debian package) - update to 4:7.4.7-1+deb12u6
app-office/libreoffice - update to 24.2.7.2-r1
app-office/libreoffice-bin - update to 24.8.4

External References

Related Security Bulletins