First published: Mon Dec 11 2023(Updated: )
Reginaldo Silva discovered that LibreOffice incorrectly handled filenames when passing embedded videos to GStreamer. If a user were tricked into opening a specially crafted file, a remote attacker could possibly use this issue to execute arbitrary GStreamer plugins. (CVE-2023-6185) Reginaldo Silva discovered that LibreOffice incorrectly handled certain non-typical hyperlinks. If a user were tricked into opening a specially crafted file, a remote attacker could possibly use this issue to execute arbitrary scripts. (CVE-2023-6186)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libreoffice | <4:7.6.4-0ubuntu0.23.10.1 | 4:7.6.4-0ubuntu0.23.10.1 |
=23.10 | ||
All of | ||
ubuntu/libreoffice | <4:7.5.9-0ubuntu0.23.04.1 | 4:7.5.9-0ubuntu0.23.04.1 |
=23.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.