Back to search
CVE-2024-12425
Published: Jan 7, 2025
Modified: Nov 3, 2025
PUBLISHED
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4.
| Vendor | Product | Versions |
|---|---|---|
The Document Foundation | LibreOffice | affected 24.8 - < < 24.8.4 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now