Vulnerabilities in LibreOffice that allow the execution of Gstreamer scripts or plugins

Information has been revealed regarding two vulnerabilities in the free office suite LibreOffice, which have been assigned a high danger level (8.3 out of 10). The issues were addressed in recent updates of LibreOffice 7.6.4 and 7.5.9.

The first vulnerability (CVE-2023-6186) allows the execution of arbitrary scripts when a user clicks on a specially crafted link in a document that triggers built-in macros or internal commands. In certain situations, it was possible to prevent the display of a preliminary warning about the action when clicking such links.

The second vulnerability (CVE-2023-6185) allows the execution of arbitrary Gstreamer plugins on Linux platforms by opening a document with specially formatted embedded video. The problem is caused by insufficient escaping of special characters in the video filename before calling Gstreamer.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster