CVE Database
/

CVE-2024-12425

Back to search

CVE-2024-12425

Published: Jan 7, 2025

Modified: Nov 3, 2025

PUBLISHED

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files. This issue affects LibreOffice: from 24.8 before < 24.8.4.

VendorProductVersions

The Document Foundation

LibreOffice

affected
24.8 - < < 24.8.4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now