CVE-2006-3117
published 2006-06-30CVE-2006-3117: Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code…
PriorityP335high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
4.27%
90.0th percentile
Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability."
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openoffice | openoffice | — | — |
| openoffice | openoffice | — | — |
| openoffice | openoffice | — | — |
| openoffice | openoffice | — | — |
| openoffice | openoffice | — | — |
| openoffice | openoffice | — | — |
| openoffice | openoffice | — | — |
| openoffice | openoffice | — | — |
| openoffice | openoffice | — | — |
| sun | staroffice | — | — |
| sun | staroffice | — | — |
| sun | staroffice | — | — |
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_redhat7.6HIGH
vendor_ubuntu7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenOffice.org vulnerabilities
vendor_ubuntu·2006-07-19·CVSS 7.6
CVE-2006-2198 [HIGH] OpenOffice.org vulnerabilities
Title: OpenOffice.org vulnerabilities
Summary: OpenOffice.org vulnerabilities
USN-313-1 fixed several vulnerabilities in OpenOffice for Ubuntu 5.04 and
Ubuntu 6.06 LTS. This followup advisory provides the corresponding
update for Ubuntu 5.10.
For reference, these are the details of the original USN:
It was possible to embed Basic macros in documents in a way that
OpenOffice.org would not ask for confirmation about executing them. By
tricking a user into opening a malicious document, this could be
exploited to run arbitrary Basic code (including local file access and
modification) with the user's privileges. (CVE-2006-2198)
A flaw was discovered in the Java sandbox which allowed Java applets
to break out of the sandbox and execute code without restrictions. By
tricking a user into open
Ubuntu
OpenOffice.org vulnerabilities
vendor_ubuntu·2006-07-12·CVSS 7.6
CVE-2006-3117 [HIGH] OpenOffice.org vulnerabilities
Title: OpenOffice.org vulnerabilities
Summary: OpenOffice.org vulnerabilities
It was possible to embed Basic macros in documents in a way that
OpenOffice.org would not ask for confirmation about executing them. By
tricking a user into opening a malicious document, this could be
exploited to run arbitrary Basic code (including local file access and
modification) with the user's privileges. (CVE-2006-2198)
A flaw was discovered in the Java sandbox which allowed Java applets
to break out of the sandbox and execute code without restrictions. By
tricking a user into opening a malicious document, this could be
exploited to run arbitrary code with the user's privileges. This
update disables Java applets for OpenOffice.org, since it is not
generally possible to guarantee the sandbox restriction
Red Hat
security flaw
vendor_redhat·2006-06-29·CVSS 7.6
CVE-2006-3117 [HIGH] security flaw
security flaw
Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability."
GHSA
GHSA-9hrj-83rp-h2c6: Heap-based buffer overflow in OpenOffice
ghsa_unreviewed·2022-05-01
CVE-2006-3117 [HIGH] CWE-119 GHSA-9hrj-83rp-h2c6: Heap-based buffer overflow in OpenOffice
Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-3117 security flaw
bugzilla·2018-08-16·CVSS 7.6
CVE-2006-3117 [HIGH] CVE-2006-3117 security flaw
CVE-2006-3117 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability."
Bugzilla
CVE-2006-2198 various OOo advisories (CVE-2006-2199, CVE-2006-3117)
bugzilla·2006-06-26·CVSS 7.6
CVE-2006-2198 [HIGH] CVE-2006-2198 various OOo advisories (CVE-2006-2199, CVE-2006-3117)
CVE-2006-2198 various OOo advisories (CVE-2006-2199, CVE-2006-3117)
*** This bug has been marked as a duplicate of 196679 ***
Bugzilla
CVE-2006-2198 various OOo advisories (CVE-2006-2199, CVE-2006-3117)
bugzilla·2006-06-26·CVSS 7.6
CVE-2006-2198 [HIGH] CVE-2006-2198 various OOo advisories (CVE-2006-2199, CVE-2006-3117)
CVE-2006-2198 various OOo advisories (CVE-2006-2199, CVE-2006-3117)
CVE-2006-2198:
After all that news about Stardust, some Sun security specialist did some
deeper security audits in StarOffice. And he did a really great job on that!
He found a solution to put macros into document locations where our
application framework doesn't expect them.
The macros can be contained there for some historical reasons, and some
other code is starting the execution without checking permissions.
The macro will be executed when loading the document, even if macros are
disabled, without any user interaction!
CVE-2006-2199:
There was an other thing our security specialist found out.
It is possible to write Java applets that breaks out of the sandbox!
People here in StarOffice engineering think the best
http://fedoranews.org/cms/node/2343http://secunia.com/advisories/20867http://secunia.com/advisories/20893http://secunia.com/advisories/20910http://secunia.com/advisories/20911http://secunia.com/advisories/20913http://secunia.com/advisories/20975http://secunia.com/advisories/20995http://secunia.com/advisories/21278http://secunia.com/advisories/22129http://secunia.com/advisories/23620http://security.gentoo.org/glsa/glsa-200607-12.xmlhttp://securitytracker.com/id?1016414http://sunsolve.sun.com/search/document.do?assetkey=1-26-102501-1http://www.debian.org/security/2006/dsa-1104http://www.mandriva.com/security/advisories?name=MDKSA-2006:118http://www.ngssoftware.com/advisories/openoffice.txthttp://www.novell.com/linux/security/advisories/2006_40_openoffice.htmlhttp://www.openoffice.org/security/CVE-2006-3117.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0573.htmlhttp://www.securityfocus.com/archive/1/447035/100/0/threadedhttp://www.securityfocus.com/bid/18739http://www.ubuntu.com/usn/usn-313-1http://www.ubuntu.com/usn/usn-313-2http://www.vupen.com/english/advisories/2006/2607http://www.vupen.com/english/advisories/2006/2621https://exchange.xforce.ibmcloud.com/vulnerabilities/27571https://issues.rpath.com/browse/RPL-475https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9704http://fedoranews.org/cms/node/2343http://secunia.com/advisories/20867http://secunia.com/advisories/20893http://secunia.com/advisories/20910http://secunia.com/advisories/20911http://secunia.com/advisories/20913http://secunia.com/advisories/20975http://secunia.com/advisories/20995http://secunia.com/advisories/21278http://secunia.com/advisories/22129http://secunia.com/advisories/23620http://security.gentoo.org/glsa/glsa-200607-12.xmlhttp://securitytracker.com/id?1016414http://sunsolve.sun.com/search/document.do?assetkey=1-26-102501-1http://www.debian.org/security/2006/dsa-1104http://www.mandriva.com/security/advisories?name=MDKSA-2006:118http://www.ngssoftware.com/advisories/openoffice.txthttp://www.novell.com/linux/security/advisories/2006_40_openoffice.htmlhttp://www.openoffice.org/security/CVE-2006-3117.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0573.htmlhttp://www.securityfocus.com/archive/1/447035/100/0/threadedhttp://www.securityfocus.com/bid/18739http://www.ubuntu.com/usn/usn-313-1http://www.ubuntu.com/usn/usn-313-2http://www.vupen.com/english/advisories/2006/2607http://www.vupen.com/english/advisories/2006/2621https://exchange.xforce.ibmcloud.com/vulnerabilities/27571https://issues.rpath.com/browse/RPL-475https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9704
2006-06-30
Published