LibreOffice GStreamer IIV Arbitrary Plugin Execution
CVE-2023-6185 Published on December 11, 2023
Improper input validation enabling arbitrary Gstreamer pipeline injection
Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins.
In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.
Vulnerability Analysis
Products Associated with CVE-2023-6185
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2023-6185 are published in these products:
Affected Versions
The Document Foundation LibreOffice:- Version 7.5 and below 7.5.9 is affected.
- Version 7.6 and below 7.6.3 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.