Vulnerability Description
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Powerpoint | 2003 |
References
- http://blogs.technet.com/msrc/archive/2006/10/12/poc-published-for-ms-office-200
- http://blogs.technet.com/msrc/archive/2006/11/10/follow-up-information-on-weblog
- http://research.eeye.com/html/alerts/zeroday/20061012_2.html
- http://secunia.com/advisories/22394Vendor Advisory
- http://securitytracker.com/id?1017059
- http://www.informationweek.com/management/showArticle.jhtml?articleID=193302553
- http://www.osvdb.org/29720
- http://www.securityfocus.com/bid/20495Exploit
- http://www.vupen.com/english/advisories/2006/4031
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29507
- https://www.exploit-db.com/exploits/2523
- http://blogs.technet.com/msrc/archive/2006/10/12/poc-published-for-ms-office-200
- http://blogs.technet.com/msrc/archive/2006/11/10/follow-up-information-on-weblog
- http://research.eeye.com/html/alerts/zeroday/20061012_2.html
- http://secunia.com/advisories/22394Vendor Advisory
FAQ
What is CVE-2006-5296?
CVE-2006-5296 is a vulnerability with a CVSS score of 4.3 (MEDIUM). PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL ...
How severe is CVE-2006-5296?
CVE-2006-5296 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-5296?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Powerpoint.