CVE-2023-6185: Improper input validation enabling arbitrary Gstreamer pipeline injection
Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins.
In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6185?
CVE-2023-6185 has been rated as having a high severity due to the potential for arbitrary code execution.
How do I fix CVE-2023-6185?
To fix CVE-2023-6185, users should upgrade to LibreOffice version 7.5.10 or later, or version 7.6.5 or later.
Which versions of LibreOffice are affected by CVE-2023-6185?
CVE-2023-6185 affects LibreOffice versions prior to 7.5.10 and 7.6.5.
What is the nature of the vulnerability in CVE-2023-6185?
CVE-2023-6185 is an improper input validation vulnerability that allows attackers to execute arbitrary GStreamer plugins.
Can I mitigate CVE-2023-6185 without upgrading?
There are no known effective mitigations for CVE-2023-6185 other than upgrading to a patched version.