CVE-2024-12425

Severity CVSS v4.0:
LOW
Type:
CWE-22 Path Traversal
Publication date:
07/01/2025
Last modified:
08/12/2025

Description

Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;) vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal.<br /> <br /> <br /> <br /> <br /> An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files.<br /> <br /> <br /> This issue affects LibreOffice: from 24.8 before

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* 24.8.0.1 (including) 24.8.4 (excluding)
cpe:2.3:a:libreoffice:libreoffice:24.8.0.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:24.8.0.0:beta1:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*