LibreOffice GStreamer IIV Arbitrary Plugin Execution
CVE-2023-6185 Published on December 11, 2023

Improper input validation enabling arbitrary Gstreamer pipeline injection
Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.

Vendor Advisory NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
REQUIRED
Scope:
CHANGED
Confidentiality Impact:
LOW
Integrity Impact:
HIGH
Availability Impact:
HIGH

Products Associated with CVE-2023-6185

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2023-6185 are published in these products:

 
 
 
 

Affected Versions

The Document Foundation LibreOffice:

Exploit Probability

EPSS
1.02%
Percentile
61.45%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.