SUSE update for libreoffice



Published: 2023-12-20
Risk High
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2023-6185
CVE-2023-6186
CWE-ID CWE-78
CWE-254
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
SUSE Linux Enterprise Micro
Operating systems & Components / Operating system

SUSE Linux Enterprise Workstation Extension 15
Operating systems & Components / Operating system

SUSE Package Hub 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Server for SAP Applications 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Server 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Real Time 15
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Desktop 15
Operating systems & Components / Operating system

openSUSE Leap
Operating systems & Components / Operating system

SUSE Manager Retail Branch Server
Operating systems & Components / Operating system

SUSE Manager Server
Operating systems & Components / Operating system

SUSE Manager Proxy
Operating systems & Components / Operating system

libreoffice-l10n-en
Operating systems & Components / Operating system package or component

libreoffice-l10n-xh
Operating systems & Components / Operating system package or component

libreoffice-l10n-vi
Operating systems & Components / Operating system package or component

libreoffice-l10n-ss
Operating systems & Components / Operating system package or component

libreoffice-l10n-ca_valencia
Operating systems & Components / Operating system package or component

libreoffice-l10n-as
Operating systems & Components / Operating system package or component

libreoffice-l10n-ast
Operating systems & Components / Operating system package or component

libreoffice-l10n-ga
Operating systems & Components / Operating system package or component

libreoffice-l10n-pa
Operating systems & Components / Operating system package or component

libreoffice-l10n-pl
Operating systems & Components / Operating system package or component

libreoffice-l10n-fi
Operating systems & Components / Operating system package or component

libreoffice-l10n-kab
Operating systems & Components / Operating system package or component

libreoffice-l10n-lo
Operating systems & Components / Operating system package or component

libreoffice-l10n-uk
Operating systems & Components / Operating system package or component

libreoffice-l10n-zu
Operating systems & Components / Operating system package or component

libreoffice-l10n-zh_TW
Operating systems & Components / Operating system package or component

libreoffice-l10n-bo
Operating systems & Components / Operating system package or component

libreoffice-l10n-he
Operating systems & Components / Operating system package or component

libreoffice-l10n-mk
Operating systems & Components / Operating system package or component

libreoffice-l10n-ne
Operating systems & Components / Operating system package or component

libreoffice-l10n-ko
Operating systems & Components / Operating system package or component

libreoffice-l10n-mr
Operating systems & Components / Operating system package or component

libreoffice-l10n-mai
Operating systems & Components / Operating system package or component

libreoffice-l10n-hsb
Operating systems & Components / Operating system package or component

libreoffice-l10n-nso
Operating systems & Components / Operating system package or component

libreoffice-l10n-nl
Operating systems & Components / Operating system package or component

libreoffice-l10n-bn
Operating systems & Components / Operating system package or component

libreoffice-l10n-mni
Operating systems & Components / Operating system package or component

libreoffice-l10n-or
Operating systems & Components / Operating system package or component

libreoffice-l10n-om
Operating systems & Components / Operating system package or component

libreoffice-l10n-be
Operating systems & Components / Operating system package or component

libreoffice-l10n-bn_IN
Operating systems & Components / Operating system package or component

libreoffice-l10n-is
Operating systems & Components / Operating system package or component

libreoffice-l10n-hu
Operating systems & Components / Operating system package or component

libreoffice-l10n-szl
Operating systems & Components / Operating system package or component

libreoffice-l10n-my
Operating systems & Components / Operating system package or component

libreoffice-l10n-fur
Operating systems & Components / Operating system package or component

libreoffice-l10n-da
Operating systems & Components / Operating system package or component

libreoffice-l10n-lt
Operating systems & Components / Operating system package or component

libreoffice-l10n-nb
Operating systems & Components / Operating system package or component

libreoffice-l10n-ks
Operating systems & Components / Operating system package or component

libreoffice-l10n-sw_TZ
Operating systems & Components / Operating system package or component

libreoffice-l10n-dgo
Operating systems & Components / Operating system package or component

libreoffice-l10n-it
Operating systems & Components / Operating system package or component

libreoffice-l10n-ug
Operating systems & Components / Operating system package or component

libreoffice-l10n-dz
Operating systems & Components / Operating system package or component

libreoffice-l10n-pt_BR
Operating systems & Components / Operating system package or component

libreoffice-l10n-el
Operating systems & Components / Operating system package or component

libreoffice-l10n-sl
Operating systems & Components / Operating system package or component

libreoffice-l10n-ru
Operating systems & Components / Operating system package or component

libreoffice-l10n-en_GB
Operating systems & Components / Operating system package or component

libreoffice-l10n-zh_CN
Operating systems & Components / Operating system package or component

libreoffice-l10n-de
Operating systems & Components / Operating system package or component

libreoffice-l10n-sat
Operating systems & Components / Operating system package or component

libreoffice-l10n-et
Operating systems & Components / Operating system package or component

libreoffice-l10n-sd
Operating systems & Components / Operating system package or component

libreoffice-l10n-uz
Operating systems & Components / Operating system package or component

libreoffice-l10n-br
Operating systems & Components / Operating system package or component

libreoffice-l10n-sv
Operating systems & Components / Operating system package or component

libreoffice-l10n-nr
Operating systems & Components / Operating system package or component

libreoffice-l10n-ve
Operating systems & Components / Operating system package or component

libreoffice-l10n-gl
Operating systems & Components / Operating system package or component

libreoffice-l10n-dsb
Operating systems & Components / Operating system package or component

libreoffice-l10n-te
Operating systems & Components / Operating system package or component

libreoffice-l10n-ca
Operating systems & Components / Operating system package or component

libreoffice-l10n-lb
Operating systems & Components / Operating system package or component

libreoffice-l10n-ka
Operating systems & Components / Operating system package or component

libreoffice-l10n-mn
Operating systems & Components / Operating system package or component

libreoffice-l10n-tg
Operating systems & Components / Operating system package or component

libreoffice-l10n-sr
Operating systems & Components / Operating system package or component

libreoffice-l10n-ta
Operating systems & Components / Operating system package or component

libreoffice-l10n-kok
Operating systems & Components / Operating system package or component

libreoffice-l10n-sk
Operating systems & Components / Operating system package or component

libreoffice-l10n-th
Operating systems & Components / Operating system package or component

libreoffice-l10n-nn
Operating systems & Components / Operating system package or component

libreoffice-l10n-cs
Operating systems & Components / Operating system package or component

libreoffice-icon-themes
Operating systems & Components / Operating system package or component

libreoffice-l10n-vec
Operating systems & Components / Operating system package or component

libreoffice-l10n-gu
Operating systems & Components / Operating system package or component

libreoffice-l10n-fr
Operating systems & Components / Operating system package or component

libreoffice-l10n-hi
Operating systems & Components / Operating system package or component

libreoffice-l10n-tn
Operating systems & Components / Operating system package or component

libreoffice-glade
Operating systems & Components / Operating system package or component

libreoffice-l10n-ts
Operating systems & Components / Operating system package or component

libreoffice-l10n-tr
Operating systems & Components / Operating system package or component

libreoffice-l10n-es
Operating systems & Components / Operating system package or component

libreoffice-l10n-ro
Operating systems & Components / Operating system package or component

libreoffice-l10n-ckb
Operating systems & Components / Operating system package or component

libreoffice-l10n-ja
Operating systems & Components / Operating system package or component

libreoffice-l10n-oc
Operating systems & Components / Operating system package or component

libreoffice-l10n-id
Operating systems & Components / Operating system package or component

libreoffice-l10n-cy
Operating systems & Components / Operating system package or component

libreoffice-l10n-sq
Operating systems & Components / Operating system package or component

libreoffice-l10n-gug
Operating systems & Components / Operating system package or component

libreoffice-l10n-sa_IN
Operating systems & Components / Operating system package or component

libreoffice-l10n-pt_PT
Operating systems & Components / Operating system package or component

libreoffice-l10n-fy
Operating systems & Components / Operating system package or component

libreoffice-l10n-tt
Operating systems & Components / Operating system package or component

libreoffice-l10n-ml
Operating systems & Components / Operating system package or component

libreoffice-l10n-lv
Operating systems & Components / Operating system package or component

libreoffice-l10n-af
Operating systems & Components / Operating system package or component

libreoffice-l10n-bs
Operating systems & Components / Operating system package or component

libreoffice-l10n-brx
Operating systems & Components / Operating system package or component

libreoffice-l10n-kk
Operating systems & Components / Operating system package or component

libreoffice-l10n-st
Operating systems & Components / Operating system package or component

libreoffice-l10n-en_ZA
Operating systems & Components / Operating system package or component

libreoffice-l10n-sid
Operating systems & Components / Operating system package or component

libreoffice-l10n-kn
Operating systems & Components / Operating system package or component

libreoffice-l10n-rw
Operating systems & Components / Operating system package or component

libreoffice-l10n-hr
Operating systems & Components / Operating system package or component

libreoffice-l10n-km
Operating systems & Components / Operating system package or component

libreoffice-l10n-bg
Operating systems & Components / Operating system package or component

libreoffice-l10n-fa
Operating systems & Components / Operating system package or component

libreoffice-l10n-eu
Operating systems & Components / Operating system package or component

libreoffice-l10n-am
Operating systems & Components / Operating system package or component

libreoffice-l10n-gd
Operating systems & Components / Operating system package or component

libreoffice-l10n-kmr_Latn
Operating systems & Components / Operating system package or component

libreoffice-gdb-pretty-printers
Operating systems & Components / Operating system package or component

libreoffice-l10n-si
Operating systems & Components / Operating system package or component

libreoffice-l10n-eo
Operating systems & Components / Operating system package or component

libreoffice-branding-upstream
Operating systems & Components / Operating system package or component

libreoffice-l10n-ar
Operating systems & Components / Operating system package or component

libreoffice-sdk
Operating systems & Components / Operating system package or component

libreoffice-gtk3-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-base-drivers-postgresql
Operating systems & Components / Operating system package or component

libreoffice-base-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-pyuno-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-draw
Operating systems & Components / Operating system package or component

libreofficekit
Operating systems & Components / Operating system package or component

libreoffice-gnome
Operating systems & Components / Operating system package or component

libreoffice-debugsource
Operating systems & Components / Operating system package or component

libreoffice-calc-extensions
Operating systems & Components / Operating system package or component

libreoffice-gtk3
Operating systems & Components / Operating system package or component

libreoffice-draw-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-base-drivers-postgresql-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-librelogo
Operating systems & Components / Operating system package or component

libreoffice-qt5-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-calc-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-writer-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-gnome-debuginfo
Operating systems & Components / Operating system package or component

libreofficekit-devel
Operating systems & Components / Operating system package or component

libreoffice-calc
Operating systems & Components / Operating system package or component

libreoffice-qt5
Operating systems & Components / Operating system package or component

libreoffice-officebean
Operating systems & Components / Operating system package or component

libreoffice-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-math
Operating systems & Components / Operating system package or component

libreoffice
Operating systems & Components / Operating system package or component

libreoffice-sdk-doc
Operating systems & Components / Operating system package or component

libreoffice-impress
Operating systems & Components / Operating system package or component

libreoffice-sdk-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-mailmerge
Operating systems & Components / Operating system package or component

libreoffice-math-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-impress-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-base
Operating systems & Components / Operating system package or component

libreoffice-writer
Operating systems & Components / Operating system package or component

libreoffice-officebean-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-pyuno
Operating systems & Components / Operating system package or component

libreoffice-writer-extensions
Operating systems & Components / Operating system package or component

libreoffice-filters-optional
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) OS Command Injection

EUVDB-ID: #VU84092

Risk: High

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-6185

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of filenames of the embedded video files before passing it to gstreamer. A remote attacker can create a specially crafted document with embedded video inside, trick the victim into opening it and execute arbitrary OS commands on the system.

Mitigation

Update the affected package libreoffice to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Micro: 5.3 - 5.5

SUSE Linux Enterprise Workstation Extension 15: SP4 - SP5

SUSE Package Hub 15: 15-SP4 - 15-SP5

SUSE Linux Enterprise Server for SAP Applications 15: SP4 - SP5

SUSE Linux Enterprise Server 15: SP4 - SP5

SUSE Linux Enterprise Real Time 15: SP4 - SP5

SUSE Linux Enterprise High Performance Computing 15: SP4 - SP5

SUSE Linux Enterprise Desktop 15: SP4 - SP5

openSUSE Leap: 15.4 - 15.5

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

libreoffice-l10n-en: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-xh: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-vi: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ss: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ca_valencia: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-as: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ast: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ga: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-pa: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-pl: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-fi: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-kab: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-lo: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-uk: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-zu: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-zh_TW: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-bo: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-he: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-mk: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ne: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ko: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-mr: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-mai: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-hsb: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-nso: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-nl: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-bn: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-mni: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-or: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-om: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-be: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-bn_IN: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-is: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-hu: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-szl: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-my: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-fur: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-da: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-lt: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-nb: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ks: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sw_TZ: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-dgo: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-it: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ug: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-dz: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-pt_BR: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-el: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sl: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ru: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-en_GB: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-zh_CN: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-de: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sat: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-et: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sd: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-uz: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-br: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sv: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-nr: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ve: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-gl: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-dsb: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-te: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ca: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-lb: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ka: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-mn: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-tg: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sr: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ta: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-kok: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sk: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-th: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-nn: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-cs: before 7.6.2.1-150400.17.20.1

libreoffice-icon-themes: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-vec: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-gu: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-fr: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-hi: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-tn: before 7.6.2.1-150400.17.20.1

libreoffice-glade: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ts: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-tr: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-es: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ro: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ckb: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ja: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-oc: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-id: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-cy: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sq: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-gug: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sa_IN: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-pt_PT: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-fy: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-tt: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ml: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-lv: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-af: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-bs: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-brx: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-kk: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-st: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-en_ZA: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sid: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-kn: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-rw: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-hr: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-km: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-bg: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-fa: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-eu: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-am: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-gd: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-kmr_Latn: before 7.6.2.1-150400.17.20.1

libreoffice-gdb-pretty-printers: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-si: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-eo: before 7.6.2.1-150400.17.20.1

libreoffice-branding-upstream: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ar: before 7.6.2.1-150400.17.20.1

libreoffice-sdk: before 7.6.2.1-150400.17.20.1

libreoffice-gtk3-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-base-drivers-postgresql: before 7.6.2.1-150400.17.20.1

libreoffice-base-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-pyuno-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-draw: before 7.6.2.1-150400.17.20.1

libreofficekit: before 7.6.2.1-150400.17.20.1

libreoffice-gnome: before 7.6.2.1-150400.17.20.1

libreoffice-debugsource: before 7.6.2.1-150400.17.20.1

libreoffice-calc-extensions: before 7.6.2.1-150400.17.20.1

libreoffice-gtk3: before 7.6.2.1-150400.17.20.1

libreoffice-draw-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-base-drivers-postgresql-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-librelogo: before 7.6.2.1-150400.17.20.1

libreoffice-qt5-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-calc-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-writer-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-gnome-debuginfo: before 7.6.2.1-150400.17.20.1

libreofficekit-devel: before 7.6.2.1-150400.17.20.1

libreoffice-calc: before 7.6.2.1-150400.17.20.1

libreoffice-qt5: before 7.6.2.1-150400.17.20.1

libreoffice-officebean: before 7.6.2.1-150400.17.20.1

libreoffice-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-math: before 7.6.2.1-150400.17.20.1

libreoffice: before 7.6.2.1-150400.17.20.1

libreoffice-sdk-doc: before 7.6.2.1-150400.17.20.1

libreoffice-impress: before 7.6.2.1-150400.17.20.1

libreoffice-sdk-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-mailmerge: before 7.6.2.1-150400.17.20.1

libreoffice-math-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-impress-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-base: before 7.6.2.1-150400.17.20.1

libreoffice-writer: before 7.6.2.1-150400.17.20.1

libreoffice-officebean-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-pyuno: before 7.6.2.1-150400.17.20.1

libreoffice-writer-extensions: before 7.6.2.1-150400.17.20.1

libreoffice-filters-optional: before 7.6.2.1-150400.17.20.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234932-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Security features bypass

EUVDB-ID: #VU84093

Risk: High

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-6186

CWE-ID: CWE-254 - Security Features

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper validation of hyperlinks within the document. A remote attacker can create a specially crafted hyperlink, trick the victim into clicking on the link inside the document and execute arbitrary macro without a warning, resulting in a code execution.

Mitigation

Update the affected package libreoffice to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Micro: 5.3 - 5.5

SUSE Linux Enterprise Workstation Extension 15: SP4 - SP5

SUSE Package Hub 15: 15-SP4 - 15-SP5

SUSE Linux Enterprise Server for SAP Applications 15: SP4 - SP5

SUSE Linux Enterprise Server 15: SP4 - SP5

SUSE Linux Enterprise Real Time 15: SP4 - SP5

SUSE Linux Enterprise High Performance Computing 15: SP4 - SP5

SUSE Linux Enterprise Desktop 15: SP4 - SP5

openSUSE Leap: 15.4 - 15.5

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

libreoffice-l10n-en: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-xh: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-vi: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ss: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ca_valencia: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-as: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ast: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ga: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-pa: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-pl: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-fi: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-kab: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-lo: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-uk: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-zu: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-zh_TW: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-bo: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-he: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-mk: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ne: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ko: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-mr: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-mai: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-hsb: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-nso: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-nl: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-bn: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-mni: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-or: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-om: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-be: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-bn_IN: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-is: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-hu: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-szl: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-my: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-fur: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-da: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-lt: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-nb: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ks: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sw_TZ: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-dgo: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-it: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ug: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-dz: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-pt_BR: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-el: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sl: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ru: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-en_GB: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-zh_CN: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-de: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sat: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-et: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sd: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-uz: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-br: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sv: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-nr: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ve: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-gl: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-dsb: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-te: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ca: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-lb: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ka: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-mn: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-tg: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sr: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ta: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-kok: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sk: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-th: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-nn: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-cs: before 7.6.2.1-150400.17.20.1

libreoffice-icon-themes: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-vec: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-gu: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-fr: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-hi: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-tn: before 7.6.2.1-150400.17.20.1

libreoffice-glade: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ts: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-tr: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-es: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ro: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ckb: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ja: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-oc: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-id: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-cy: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sq: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-gug: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sa_IN: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-pt_PT: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-fy: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-tt: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ml: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-lv: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-af: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-bs: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-brx: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-kk: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-st: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-en_ZA: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-sid: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-kn: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-rw: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-hr: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-km: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-bg: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-fa: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-eu: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-am: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-gd: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-kmr_Latn: before 7.6.2.1-150400.17.20.1

libreoffice-gdb-pretty-printers: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-si: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-eo: before 7.6.2.1-150400.17.20.1

libreoffice-branding-upstream: before 7.6.2.1-150400.17.20.1

libreoffice-l10n-ar: before 7.6.2.1-150400.17.20.1

libreoffice-sdk: before 7.6.2.1-150400.17.20.1

libreoffice-gtk3-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-base-drivers-postgresql: before 7.6.2.1-150400.17.20.1

libreoffice-base-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-pyuno-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-draw: before 7.6.2.1-150400.17.20.1

libreofficekit: before 7.6.2.1-150400.17.20.1

libreoffice-gnome: before 7.6.2.1-150400.17.20.1

libreoffice-debugsource: before 7.6.2.1-150400.17.20.1

libreoffice-calc-extensions: before 7.6.2.1-150400.17.20.1

libreoffice-gtk3: before 7.6.2.1-150400.17.20.1

libreoffice-draw-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-base-drivers-postgresql-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-librelogo: before 7.6.2.1-150400.17.20.1

libreoffice-qt5-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-calc-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-writer-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-gnome-debuginfo: before 7.6.2.1-150400.17.20.1

libreofficekit-devel: before 7.6.2.1-150400.17.20.1

libreoffice-calc: before 7.6.2.1-150400.17.20.1

libreoffice-qt5: before 7.6.2.1-150400.17.20.1

libreoffice-officebean: before 7.6.2.1-150400.17.20.1

libreoffice-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-math: before 7.6.2.1-150400.17.20.1

libreoffice: before 7.6.2.1-150400.17.20.1

libreoffice-sdk-doc: before 7.6.2.1-150400.17.20.1

libreoffice-impress: before 7.6.2.1-150400.17.20.1

libreoffice-sdk-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-mailmerge: before 7.6.2.1-150400.17.20.1

libreoffice-math-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-impress-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-base: before 7.6.2.1-150400.17.20.1

libreoffice-writer: before 7.6.2.1-150400.17.20.1

libreoffice-officebean-debuginfo: before 7.6.2.1-150400.17.20.1

libreoffice-pyuno: before 7.6.2.1-150400.17.20.1

libreoffice-writer-extensions: before 7.6.2.1-150400.17.20.1

libreoffice-filters-optional: before 7.6.2.1-150400.17.20.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234932-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###