Information disclosure in LibreOffice - CVE-2024-12426

 

Information disclosure in LibreOffice - CVE-2024-12426

Published: January 7, 2025


Vulnerability identifier: #VU102417
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-12426
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to application allows to dynamically create links to external websites using information from environmental variables or INI file values. A remote attacker can trick the victim into opening a specially crafted documents and then clicking on the link in that document to gain access to potentially sensitive information.


Affected software

LibreOffice
Debian Linux
Gentoo Linux
Ubuntu
libreoffice (Ubuntu package)
libreoffice (Debian package)
app-office/libreoffice
app-office/libreoffice-bin

How to mitigate CVE-2024-12426

Install updates from vendor's website.

LibreOffice - update to 24.8.4.1
libreoffice (Ubuntu package) - addressed in versions 1:6.4.7-0ubuntu0.20.04.13, 1:7.3.7-0ubuntu0.22.04.8, 4:24.2.7-0ubuntu0.24.04.2, 4:24.8.4-0ubuntu0.24.10.2
libreoffice (Debian package) - update to 4:7.4.7-1+deb12u6
app-office/libreoffice - update to 24.2.7.2-r1
app-office/libreoffice-bin - update to 24.8.4

External References

Related Security Bulletins