ELA-1026-1 libreoffice security update

Improper Input Validation

2023-12-31
Packagelibreoffice
Version1:4.3.3-2+deb8u15 (jessie)
Related CVEs CVE-2023-6185


An Improper Input Validation vulnerability was found in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.



For Debian 8 jessie, these problems have been fixed in version 1:4.3.3-2+deb8u15.

We recommend that you upgrade your libreoffice packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.