CVE-2024-12426
published 2025-01-07CVE-2024-12426: Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice. URLs could be…
PriorityP434medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.54%
41.7th percentile
Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice.
URLs could be constructed which expanded environmental variables or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links.
This issue affects LibreOffice: from 24.8 before < 24.8.4.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | < 4.1.16 | 4.1.16 |
| apache_software_foundation | apache_openoffice | <= 4.1.15 | — |
| debian | debian_linux | — | — |
| debian | libreoffice | < libreoffice 4:7.4.7-1+deb12u6 (bookworm) | libreoffice 4:7.4.7-1+deb12u6 (bookworm) |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | >= 0 < 1:7.0.4-4+deb11u12 | 1:7.0.4-4+deb11u12 |
| libreoffice | libreoffice | >= 0 < 4:7.4.7-1+deb12u6 | 4:7.4.7-1+deb12u6 |
| libreoffice | libreoffice | >= 0 < 4:24.8.4-1 | 4:24.8.4-1 |
| libreoffice | libreoffice | >= 0 < 4:24.8.4-1 | 4:24.8.4-1 |
| libreoffice | libreoffice | >= 0 < 1:6.4.7-0ubuntu0.20.04.13 | 1:6.4.7-0ubuntu0.20.04.13 |
| libreoffice | libreoffice | >= 0 < 1:7.3.7-0ubuntu0.22.04.8 | 1:7.3.7-0ubuntu0.22.04.8 |
| libreoffice | libreoffice | >= 0 < 4:24.2.7-0ubuntu0.24.04.2 | 4:24.2.7-0ubuntu0.24.04.2 |
| libreoffice | libreoffice | >= 24.8.0.1 < 24.8.4 | 24.8.4 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv4.06.7MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.7MEDIUM
vendor_debian6.7MEDIUM
vendor_redhat6.7MEDIUM
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LibreOffice vulnerabilities
vendor_ubuntu·2025-01-27·CVSS 3.3
CVE-2024-12426 [LOW] LibreOffice vulnerabilities
Title: LibreOffice vulnerabilities
Summary: Several security issues were fixed in LibreOffice.
Thomas Rinsma discovered that LibreOffice incorrectly handled paths when
processing embedded font files. If a user or automated system were tricked
into opening a specially crafted LibreOffice file, a remote attacker could
possibly use this issue to create arbitrary files ending with ".ttf".
(CVE-2024-12425)
Thomas Rinsma discovered that LibreOffice incorrectly handled certain
environment variables and INI file values. If a user or automated system
were tricked into opening a specially crafted LibreOffice file, a remote
attacker could possibly use this issue to exfiltrate sensitive information.
(CVE-2024-12426)
Instructions: In general, a standard system update will make all the necessary cha
Red Hat
LibreOffice: URL fetching can be used to exfiltrate arbitrary INI file values and environment variables
vendor_redhat·2025-01-07·CVSS 6.7
CVE-2024-12426 [MEDIUM] CWE-200 LibreOffice: URL fetching can be used to exfiltrate arbitrary INI file values and environment variables
LibreOffice: URL fetching can be used to exfiltrate arbitrary INI file values and environment variables
Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice.
URLs could be constructed which expanded environmental variables or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links.
This issue affects LibreOffice: from 24.8 before < 24.8.4.
A flaw was found in LibreOffice. This issue may allow the exposure of environmental variables and arbitrary INI file values, leading to sensitive information disclosure via crafted URLs embedded in documents.
Package: libreoffice (Red Hat Enterprise Linux 6) - Not affected
Package
Debian
CVE-2024-12426: libreoffice - Exposure of Environmental Variables and arbitrary INI file values to an Unauthor...
vendor_debian·2024·CVSS 6.7
CVE-2024-12426 [MEDIUM] CVE-2024-12426: libreoffice - Exposure of Environmental Variables and arbitrary INI file values to an Unauthor...
Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice. URLs could be constructed which expanded environmental variables or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. This issue affects LibreOffice: from 24.8 before < 24.8.4.
Scope: local
bookworm: resolved (fixed in 4:7.4.7-1+deb12u6)
bullseye: resolved (fixed in 1:7.0.4-4+deb11u12)
forky: resolved (fixed in 4:24.8.4-1)
sid: resolved (fixed in 4:24.8.4-1)
trixie: resolved (fixed in 4:24.8.4-1)
GHSA
GHSA-wgcp-cg6f-7679: Apache OpenOffice documents can contain links
ghsa_unreviewed·2025-11-12·CVSS 6.7
CVE-2025-64407 [MEDIUM] CWE-201 GHSA-wgcp-cg6f-7679: Apache OpenOffice documents can contain links
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links
to be loaded without prompt. Such links could also be used to transmit system information, such as environment variables or configuration settings.
In the affected versions of Apache OpenOffice, documents that used a certain URI scheme linking to external files would
load the contents of such files without prompting the user for
permission to do so. Such URI scheme allows to include system configuration data, that is not supposed to be transmitted externally.
This issue affects Apache OpenOffice: through 4.1.15.
Users are recommended to upgrade to version 4.1.16, which fixes the issue.
The LibreOffice suite re
OSV
libreoffice vulnerabilities
osv·2025-01-27·CVSS 2.4
CVE-2024-12425 [LOW] libreoffice vulnerabilities
libreoffice vulnerabilities
Thomas Rinsma discovered that LibreOffice incorrectly handled paths when
processing embedded font files. If a user or automated system were tricked
into opening a specially crafted LibreOffice file, a remote attacker could
possibly use this issue to create arbitrary files ending with ".ttf".
(CVE-2024-12425)
Thomas Rinsma discovered that LibreOffice incorrectly handled certain
environment variables and INI file values. If a user or automated system
were tricked into opening a specially crafted LibreOffice file, a remote
attacker could possibly use this issue to exfiltrate sensitive information.
(CVE-2024-12426)
OSV
CVE-2024-12426: Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice
osv·2025-01-07·CVSS 6.7
CVE-2024-12426 [MEDIUM] CVE-2024-12426: Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice
Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice. URLs could be constructed which expanded environmental variables or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. This issue affects LibreOffice: from 24.8 before < 24.8.4.
GHSA
GHSA-x7m8-vrfv-272v: Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice
ghsa_unreviewed·2025-01-07
CVE-2024-12426 [MEDIUM] CWE-200 GHSA-x7m8-vrfv-272v: Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice
Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice.
URLs could be constructed which expanded environmental variables or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links.
This issue affects LibreOffice: from 24.8 before < 24.8.4.
No detection rules found.
No public exploits indexed.
2025-01-07
Published