Описание
Security update for libreoffice
This update for libreoffice fixes the following issues:
- CVE-2023-6186: Fixed link targets allow arbitrary script execution (bsc#1217578).
- CVE-2023-6185: Fixed Improper input validation enabling arbitrary Gstreamer pipeline injection (bsc#1217577).
Список пакетов
SUSE Linux Enterprise Software Development Kit 12 SP5
SUSE Linux Enterprise Workstation Extension 12 SP5
Ссылки
- Link for SUSE-SU-2023:4984-1
- E-Mail link for SUSE-SU-2023:4984-1
- SUSE Security Ratings
- SUSE Bug 1217577
- SUSE Bug 1217578
- SUSE CVE CVE-2023-6185 page
- SUSE CVE CVE-2023-6186 page
Описание
Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.
Затронутые продукты
Ссылки
- CVE-2023-6185
- SUSE Bug 1217577
Описание
Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.
Затронутые продукты
Ссылки
- CVE-2023-6186
- SUSE Bug 1217578