Superseded
by libreoffice - 4:24.2.7-0ubuntu0.24.04.4~lo1
Published
Changelog
libreoffice (4:24.2.7-0ubuntu0.24.04.2~lo2) noble; urgency=medium
* SECURITY UPDATE: Path traversal leading to arbitrary .ttf file write
- debian/patches/CVE-2024-12425.patch: be conservative on allowed temp
font names
- CVE-2024-12425
* SECURITY UPDATE: URL fetching can be used to exfiltrate arbitrary INI
file values and environment variables
- debian/patches/CVE-2024-12426-1.patch: consider VndSunStarExpand an
exotic protocol
- debian/patches/CVE-2024-12426-2.patch: look at 'embedded' protocols too
- debian/patches/CVE-2024-12426-3.patch: Fix check for further exotic
protocols
- CVE-2024-12426
-- Rico Tzschichholz <email address hidden> Mon, 20 Jan 2025 09:58:29 +0100
Available diffs
diff from 4:24.2.7-0ubuntu0.24.04.2~lo1 to 4:24.2.7-0ubuntu0.24.04.2~lo2 (pending)