Publishing details

Changelog

libreoffice (4:24.2.7-0ubuntu0.24.04.2~lo2) noble; urgency=medium

  * SECURITY UPDATE: Path traversal leading to arbitrary .ttf file write
    - debian/patches/CVE-2024-12425.patch: be conservative on allowed temp
      font names
    - CVE-2024-12425
  * SECURITY UPDATE: URL fetching can be used to exfiltrate arbitrary INI
      file values and environment variables
    - debian/patches/CVE-2024-12426-1.patch: consider VndSunStarExpand an
      exotic protocol
    - debian/patches/CVE-2024-12426-2.patch: look at 'embedded' protocols too
    - debian/patches/CVE-2024-12426-3.patch: Fix check for further exotic
      protocols
    - CVE-2024-12426

 -- Rico Tzschichholz <email address hidden>  Mon, 20 Jan 2025 09:58:29 +0100

Available diffs

Builds

Package files