← back
CVE-2023-6185

Improper input validation enabling arbitrary Gstreamer pipeline injection

CVSS 8.3 HIGHEPSS 1.0%
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.3EPSS 1.0%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
11 Dec 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →