Bug 8578 - [Anolis OS 8] Bugfix for CVE-2023-6185
Summary: [Anolis OS 8] Bugfix for CVE-2023-6185
Status: NEW
Alias: None
Product: Anolis OS 8
Classification: Anolis OS
Component: BaseOS Packages (show other bugs) BaseOS Packages
Version: 8.6
Hardware: All Linux
: P2-High S2-major
Target Milestone: ---
Assignee: wangkaiqiang
QA Contact: shuming
URL:
Whiteboard:
Keywords: CVE
Depends on:
Blocks:
 
Reported: 2024-03-20 10:29 UTC by 小龙
Modified: 2024-03-22 16:13 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description 小龙 admin 2024-03-20 10:29:15 UTC
Description:
Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins.

In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.



Broken commit info:

Bugfix commit info:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QB7UB6CTWQUDOE657OVVRSDYUY3IPBJG/
https://www.libreoffice.org/about-us/security/advisories/cve-2023-6185
https://www.debian.org/security/2023/dsa-5574