USN-6546-1: LibreOffice vulnerabilities
Reginaldo Silva discovered that LibreOffice incorrectly handled filenames when passing embedded videos to GStreamer. If a user were tricked into opening a specially crafted file, a remote attacker could possibly use this issue to execute arbitrary GStreamer plugins. (CVE-2023-6185) Reginaldo Silva discovered that LibreOffice incorrectly handled certain non-typical hyperlinks. If a user were tricked into opening a specially crafted file, a remote attacker could possibly use this issue to execute arbitrary scripts. (CVE-2023-6186)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6546-1?
The severity of USN-6546-1 is classified as potentially high due to the possibility of arbitrary code execution via specially crafted files.
How do I fix USN-6546-1?
To fix USN-6546-1, update LibreOffice to version 4:7.6.4-0ubuntu0.23.10.1 or later for Ubuntu 23.10 and 4:7.5.9-0ubuntu0.23.04.1 or later for Ubuntu 23.04.
What products are affected by USN-6546-1?
USN-6546-1 affects LibreOffice versions prior to 4:7.6.4-0ubuntu0.23.10.1 on Ubuntu 23.10 and prior to 4:7.5.9-0ubuntu0.23.04.1 on Ubuntu 23.04.
What is the exploit vector for USN-6546-1?
The exploit vector for USN-6546-1 involves tricking users into opening specially crafted files that contain embedded videos.
Is there a workaround for USN-6546-1?
There is no specific workaround for USN-6546-1; the recommended solution is to apply the necessary updates promptly.