CVE-2023-6186: Debian Linux
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.
Affected products
- Debian Debian Linux: version 11.0 only; version 12.0 only
- Fedoraproject Fedora: version 38 only
- Libreoffice Libreoffice: from 7.5.0, before 7.5.9 (fixed in 7.5.9); from 7.6.0, before 7.6.4 (fixed in 7.6.4)
Published 2023-12-11. Last modified 2026-06-17.