NA

CVE-2023-6185

Published: 11/12/2023 Updated: 31/12/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an malicious user to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an malicious user to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libreoffice libreoffice

fedoraproject fedora 38

debian debian linux 11.0

debian debian linux 12.0

Vendor Advisories

Reginaldo Silva discovered two security vulnerabilities in LibreOffice, which could result in the execution of arbitrary scripts or Gstreamer plugins when opening a malformed file For the oldstable distribution (bullseye), these problems have been fixed in version 1:704-4+deb11u8 For the stable distribution (bookworm), these problems have been ...
Description<!---->An improper input validation vulnerability was found in LibreOffice In versions where filenames are not sufficiently escaped, an attacker can execute arbitrary GStreamer pluginsAn improper input validation vulnerability was found in LibreOffice In versions where filenames are not sufficiently escaped, an attacker can execute ar ...