PT-2023-7886 · Document Foundation+10 · Libreoffice+10

Reginaldo Silva

·

Published

2023-12-11

·

Updated

2024-07-18

·

CVE-2023-6185

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibreOffice (affected versions not specified)
Description The issue is related to improper input validation in the GStreamer integration of LibreOffice, allowing an attacker to execute arbitrary GStreamer plugins. In affected versions, the filename of the embedded video is not sufficiently escaped when passed to GStreamer, enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:1427
ALSA-2024:1514
ALSA-2024:3835
ALT-PU-2023-8037
ALT-PU-2023-8057
ALT-PU-2024-1030
ALT-PU-2024-1179
BDU:2023-08957
CESA-2024_1514
CVE-2023-6185
DLA-3703-1
DSA-5574-1
INFSA-2024_3835
MGASA-2024-0116
OPENSUSE-SU-2023_4932-1
RHSA-2024:1423
RHSA-2024:1425
RHSA-2024:1427
RHSA-2024:1473
RHSA-2024:1480
RHSA-2024:1512
RHSA-2024:1513
RHSA-2024:1514
RHSA-2024:3304
RHSA-2024:3835
RHSA-2024_1427
RHSA-2024_1514
RHSA-2024_3304
RHSA-2024_3835
RLSA-2024:1427
RLSA-2024:1514
RLSA-2024:3835
SUSE-SU-2023:4932-1
SUSE-SU-2023:4984-1
SUSE-SU-2023_4984-1
USN-6546-1
USN-6546-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Libreoffice
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu