CVE Vulnerabilities

CVE-2023-6185

Published: Dec 11, 2023 | Modified: Feb 13, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.3 IMPORTANT
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins.

In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.

Affected Software

NameVendorStart VersionEnd Version
LibreofficeLibreoffice7.5.0 (including)7.5.9 (excluding)
LibreofficeLibreoffice7.6.0 (including)7.6.3 (excluding)
Red Hat Enterprise Linux 7RedHatlibreoffice-1:5.3.6.1-26.el7_9*
Red Hat Enterprise Linux 8RedHatlibreoffice-1:6.4.7.2-16.el8_9*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatlibreoffice-1:6.0.6.1-21.el8_2*
Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceRedHatlibreoffice-1:6.0.6.1-21.el8_2*
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsRedHatlibreoffice-1:6.0.6.1-21.el8_2*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatlibreoffice-1:6.4.7.2-16.el8_4*
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRedHatlibreoffice-1:6.4.7.2-16.el8_4*
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRedHatlibreoffice-1:6.4.7.2-16.el8_4*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatlibreoffice-1:6.4.7.2-16.el8_6*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatlibreoffice-1:6.4.7.2-16.el8_8*
Red Hat Enterprise Linux 9RedHatlibreoffice-1:7.1.8.1-12.el9_3*
Red Hat Enterprise Linux 9RedHatlibreoffice-1:7.1.8.1-12.el9_4*
Red Hat Enterprise Linux 9.0 Extended Update SupportRedHatlibreoffice-1:7.1.8.1-12.el9_0*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatlibreoffice-1:7.1.8.1-12.el9_2*
LibreofficeUbuntubionic*
LibreofficeUbuntudevel*
LibreofficeUbuntuesm-infra/focal*
LibreofficeUbuntufocal*
LibreofficeUbuntujammy*
LibreofficeUbuntulunar*
LibreofficeUbuntumantic*
LibreofficeUbuntutrusty*
LibreofficeUbuntuupstream*
LibreofficeUbuntuxenial*

References