HIGH · 8.3

CVE-2023-6185

Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of...

Vulnerability Description

Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.

CVSS Score

8.3

HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LibreofficeLibreoffice>= 7.5.0, < 7.5.9
FedoraprojectFedora38
DebianDebian Linux11.0

References

FAQ

What is CVE-2023-6185?

CVE-2023-6185 is a vulnerability with a CVSS score of 8.3 (HIGH). Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of...

How severe is CVE-2023-6185?

CVE-2023-6185 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-6185?

Check the references section above for vendor advisories and patch information. Affected products include: Libreoffice Libreoffice, Fedoraproject Fedora, Debian Debian Linux.