PT-2024-4414 · Curl+7 · Curl+7

Published

2024-06-25

·

Updated

2025-01-14

·

CVE-2024-5261

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LibreOffice versions prior to 24.2.4
Description The issue is related to improper certificate validation in LibreOffice's "LibreOfficeKit" mode, which disables TLS certification verification. This occurs when LibreOffice internally uses "curl" to fetch remote resources, such as images hosted on web servers, and CURLOPT SSL VERIFYPEER is set to false. In the fixed versions, curl operates in LibreOfficeKit mode with CURLOPT SSL VERIFYPEER set to true, enabling proper TLS certification verification.
Recommendations For versions prior to 24.2.4, update to version 24.2.4 or later to resolve the issue. As a temporary workaround, consider disabling the use of LibreOfficeKit mode until a patch is available. Restrict access to remote resources that may be affected by the improper certificate validation to minimize the risk of exploitation. Avoid using curl with CURLOPT SSL VERIFYPEER set to false in LibreOfficeKit mode until the issue is resolved.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

ALT-PU-2024-11573
ALT-PU-2024-14937
ALT-PU-2024-15239
BDU:2024-04913
CVE-2024-5261
MGASA-2024-0268
OPENSUSE-SU-2024:14186-1
OPENSUSE-SU-2024_3577-1
SUSE-SU-2024:3576-1
SUSE-SU-2024:3577-1
SUSE-SU-2024_3576-1
USN-6877-1

Affected Products

Alt Linux
Astra Linux
Libreoffice
Linuxmint
Red Os
Suse
Ubuntu
Curl