Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal.
An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files.
This issue affects LibreOffice: from 24.8 before < 24.8.4.
| Software | From | Fixed in |
|---|---|---|
| libreoffice / libreoffice | 24.8.0.1 | 24.8.4 |
| libreoffice / libreoffice | 24.8.0.0-alpha1 | 24.8.0.0-alpha1.x |
| libreoffice / libreoffice | 24.8.0.0-beta1 | 24.8.0.0-beta1.x |
| debian / debian_linux | 11.0 | 11.0.x |