Cyber Resilience

CVE-2023-6185

Libreoffice 7.5.0 – 7.5.9

Published
11 December 2023
Modified
13 February 2025
Patch / advisory
CVSS Score v3.1 8.3
Click a component to see what it means
Raw vectorCVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H
EPSS Score 0.010 60th percentile
Risk Priority 61 floored blend · peak EPSS

Summary

CVE-2023-6185 is a high-severity an unspecified weakness vulnerability in Libreoffice Libreoffice. Its CVSS base score is 8.3 (High).

Operationally, ranked in the top 40% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker…

more

to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-3044Same product: Debian Debian Linux
CVE-2023-6186Same product: Debian Debian Linux
CVE-2025-1080Same product: Debian Debian Linux
CVE-2023-0950Same product: Debian Debian Linux
CVE-2024-12425Same product: Debian Debian Linux
CVE-2024-12426Same product: Debian Debian Linux
CVE-2023-2255Same product: Debian Debian Linux
CVE-2019-9851Same product: Debian Debian Linux
CVE-2024-24814Same product: Debian Debian Linux
CVE-2024-26994Same product: Debian Debian Linux

Affected Assets

libreoffice
libreoffice
7.5.0 — 7.5.9 · 7.6.0 — 7.6.3
fedoraproject
fedora
38
debian
debian linux
11.0, 12.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References