Bugzilla – Bug 1235383
VUL-0: CVE-2024-12425: libreoffice: path traversal through documents with embedded font files lead to arbitrary .ttf file write
Last modified: 2025-03-20 10:30:54 UTC
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-12425 https://www.cve.org/CVERecord?id=CVE-2024-12425 https://www.libreoffice.org/about-us/security/advisories/cve-2024-12425 https://github.com/CVEProject/cvelistV5/blob/main//cves/2024/12xxx/CVE-2024-12425.json https://bugzilla.redhat.com/show_bug.cgi?id=2336110
LibreOffice 24.8.4 is currently being shipped for both SLE12-SP5 and SLE15-SP5, which fixes this issue. We'll be upgrading to 24.8.5 soon. Factory already has 25.2. So I think this is already solved, I'm reassigning back to security.