Improper input validation enabling arbitrary Gstreamer pipeline injection
CVE-2023-6185

8.8HIGH

Key Information:

Vendor
CVE Published:
11 December 2023

What is CVE-2023-6185?

The Document Foundation's LibreOffice has a vulnerability in its GStreamer integration that stems from improper input validation. Specifically, when handling embedded video files, the filename is inadequately escaped before being passed to GStreamer. This flaw enables attackers to execute arbitrary GStreamer plugins installed on a compromised system, potentially leading to further exploits or unauthorized access.

Affected Version(s)

LibreOffice 7.5 < 7.5.9

LibreOffice 7.6 < 7.6.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks to Reginaldo Silva of ubercomp.com for finding and reporting this issue
.