{"id":"CVE-2024-12425","details":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal.\n\n\n\n\nAn attacker can write to arbitrary locations, albeit suffixed with \".ttf\", by supplying a file in a format that supports embedded font files.\n\n\nThis issue affects LibreOffice: from 24.8 before \u003c 24.8.4.","modified":"2026-07-08T07:23:36.778674225Z","published":"2025-01-07T12:15:24.183Z","database_specific":{"unresolved_ranges":[{"vendor_product":"libreoffice:libreoffice","cpes":["cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"24.8.0.1"},{"fixed":"24.8.4"}],"source":"CPE_RANGE"},{"extracted_events":[{"introduced":"11.0"},{"last_affected":"11.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*"]}]},"references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2025/01/msg00013.html"},{"type":"ADVISORY","url":"https://www.libreoffice.org/about-us/security/advisories/cve-2024-12425"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libreoffice/core","events":[{"introduced":"a17e39caaf73108bee692d6f64a44c62f4066f1d"},{"last_affected":"318462181c709ed29c01eb3239b4d600d7b82ecc"}],"database_specific":{"source":"CPE_STRING","cpe":["cpe:2.3:a:libreoffice:libreoffice:24.8.0.0:alpha1:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice:24.8.0.0:beta1:*:*:*:*:*:*"],"extracted_events":[{"introduced":"24.8.0.0-alpha1"},{"last_affected":"24.8.0.0-alpha1"},{"introduced":"24.8.0.0-beta1"},{"last_affected":"24.8.0.0-beta1"}]}}],"versions":["24.8.0.0-alpha1","24.8.0.0-beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-12425.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}