CVE-2023-6185


Improper input validation enabling arbitrary Gstreamer pipeline injection

Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.



We have discovered 158 live websites that are affected by CVE-2023-6185.

Contact us to get more info




Affected Software

Product  LibreOffice
Category Content Management System
Vulnerable Versions
  • from 7.5 before 7.5.9
  • from 7.6 before 7.6.3
Total Vulnerable Versions195
Vulnerable Domains158 live websites (4.68% of LibreOffice install base)



Details

  • Published - Dec 11, 2023
  • Updated - Dec 11, 2023

Credits

  • Thanks to Reginaldo Silva of ubercomp.com for finding and reporting this issue (reporter)




Countries

United States22 websites



Germany59 websites
France13 websites
GB8 websites
Netherlands8 websites
Czech Republic5 websites
Switzerland4 websites
Cyprus3 websites
Italy3 websites
Norway3 websites

TLDs

.de42 websites
.com32 websites
.net10 websites
.org8 websites
.fr8 websites
.eu8 websites
.nl5 websites
.cz5 websites
.org.uk4 websites
.it3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2023-6185

Top websites that are affected by CVE-2023-6185. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.****.fr France***,***
*******.org United Arab Emirates***,***
**.*****.cz Czech Republic***,***
********.****.fr France*,***,***
*******.*************.net United States*,***,***
*******.nl Netherlands*,***,***
*********.net United States*,***,***
*******.com United States*,***,***
*********.******.pl Poland*,***,***
***********.de Germany*,***,***
See full domain list