Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Mageia 9: MGASA-2025-0035 critical: LibreOffice security threats

mageia
Calendar Grey February 4, 2025
Dist Mageia Esm H88
Recent LibreOffice updates for Mageia address security vulnerabilities concerning document manipulation and data leakage.
Path traversal leading to arbitrary .ttf file write

Summary

Path traversal leading to arbitrary .ttf file write. (CVE-2024-12425) URL fetching can be used to exfiltrate arbitrary INI file values and environment variables. (CVE-2024-12426)

References

- https://bugs.mageia.org/show_bug.cgi?id=33941

- https://lists.debian.org/debian-security-announce/2025/msg00008.html

- https://www.libreoffice.org/about-us/security/advisories/cve-2024-12425/

- https://www.libreoffice.org/about-us/security/advisories/cve-2024-12426/

- https://ubuntu.com/security/notices/USN-7228-1

- https://www.cve.org/CVERecord?id=CVE-2024-12425

- https://www.cve.org/CVERecord?id=CVE-2024-12426

Resolution

SRPMS

- 9/core/libreoffice-24.2.7.2-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 04 Feb 2025
URL: https://advisories.mageia.org/MGASA-2025-0035.html
Type: security
CVE: CVE-2024-12425, CVE-2024-12426

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here