Advisories ยป MGASA-2025-0035

Updated libreoffice packages fix security vulnerabilities

Publication date: 04 Feb 2025
Modification date: 04 Feb 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-12425 , CVE-2024-12426

Description

Path traversal leading to arbitrary .ttf file write. (CVE-2024-12425)
URL fetching can be used to exfiltrate arbitrary INI file values and
environment variables. (CVE-2024-12426)
                

References

SRPMS

9/core