Vulnerability Description
Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openoffice | Openoffice | 1.1.0 |
| Sun | Staroffice | 6.0 |
Related Weaknesses (CWE)
References
- http://fedoranews.org/cms/node/2343
- http://secunia.com/advisories/20867Vendor Advisory
- http://secunia.com/advisories/20893Vendor Advisory
- http://secunia.com/advisories/20910Vendor Advisory
- http://secunia.com/advisories/20911Vendor Advisory
- http://secunia.com/advisories/20913Vendor Advisory
- http://secunia.com/advisories/20975Vendor Advisory
- http://secunia.com/advisories/20995Vendor Advisory
- http://secunia.com/advisories/21278Vendor Advisory
- http://secunia.com/advisories/22129Vendor Advisory
- http://secunia.com/advisories/23620Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200607-12.xml
- http://securitytracker.com/id?1016414
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102501-1Patch
- http://www.debian.org/security/2006/dsa-1104
FAQ
What is CVE-2006-3117?
CVE-2006-3117 is a vulnerability with a CVSS score of 7.6 (HIGH). Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document th...
How severe is CVE-2006-3117?
CVE-2006-3117 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-3117?
Check the references section above for vendor advisories and patch information. Affected products include: Openoffice Openoffice, Sun Staroffice.