CVE-2006-5870
published 2006-12-31CVE-2006-5870: Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted…
PriorityP340critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
8.24%
94.3th percentile
Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openoffice | openoffice | <= 2.0.4 | — |
| sun | staroffice | — | — |
| sun | staroffice | — | — |
| sun | staroffice | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenOffice.org vulnerability
vendor_ubuntu·2007-01-12
CVE-2006-5870 OpenOffice.org vulnerability
Title: OpenOffice.org vulnerability
Summary: OpenOffice.org vulnerability
An integer overflow was discovered in OpenOffice.org's handling of WMF
files. If a user were tricked into opening a specially crafted WMF
file, an attacker could execute arbitrary code with user privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
security flaw
vendor_redhat·2007-01-03·CVSS 9.3
CVE-2006-5870 [CRITICAL] security flaw
security flaw
Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
GHSA
GHSA-564p-qwx9-wr9r: Multiple integer overflows in OpenOffice
ghsa_unreviewed·2022-05-03
CVE-2006-5870 [HIGH] GHSA-564p-qwx9-wr9r: Multiple integer overflows in OpenOffice
Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-5870 security flaw
bugzilla·2018-08-16·CVSS 9.3
CVE-2006-5870 [CRITICAL] CVE-2006-5870 security flaw
CVE-2006-5870 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.
---
Statement:
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Bugzilla
CVE-2006-5870 WMF heap overflow
bugzilla·2006-11-27·CVSS 9.3
CVE-2006-5870 [CRITICAL] CVE-2006-5870 WMF heap overflow
CVE-2006-5870 WMF heap overflow
The OpenOffice folks have a patch to catch corrupt wmf/emf files with out of
bounds values in the emf/wmf file. An attacker could create a malicious file in
such a way it may be able to execute arbitrary code if opened in OpenOffice by a
victim. Since this requires user interaction it is severity important.
http://www.openoffice.org/issues/show_bug.cgi?id=70042
Affects: RHEL3, RHEL4
Discussion:
Created attachment 142161
Proposed patch
---
Any news on this update?
---
There's a lot of building in 5 OOos :-)
RHEL-3: openoffice.org-1.1.2-35.2.0.EL3
RHEL-4: openoffice.org-1.1.5-5.6.0.EL4
RHEL-5: openoffice_org-2.0.4-5.4.12 (bug 217348)
FC-5: openoffice.org-2.0.2-5.20.2
FC-6: openoffice.org-2.0.4-5.5.7
I suspect the embargo date should be pushed out to
ftp://patches.sgi.com/support/free/security/advisories/20070101-01-P.aschttp://archives.neohapsis.com/archives/vulnwatch/2007-q1/0002.htmlyhttp://fedoranews.org/cms/node/2344http://lists.suse.com/archive/suse-security-announce/2007-Jan/0001.htmlhttp://osvdb.org/32610http://osvdb.org/32611http://secunia.com/advisories/23549http://secunia.com/advisories/23600http://secunia.com/advisories/23612http://secunia.com/advisories/23616http://secunia.com/advisories/23620http://secunia.com/advisories/23682http://secunia.com/advisories/23683http://secunia.com/advisories/23711http://secunia.com/advisories/23712http://secunia.com/advisories/23762http://secunia.com/advisories/23920http://security.gentoo.org/glsa/glsa-200701-07.xmlhttp://securitytracker.com/id?1017466http://sunsolve.sun.com/search/document.do?assetkey=1-26-102735-1http://www.debian.org/security/2007/dsa-1246http://www.kb.cert.org/vuls/id/220288http://www.mandriva.com/security/advisories?name=MDKSA-2007:006http://www.ngssoftware.com/advisories/high-risk-vulnerabilities-in-the-staroffice-suite/http://www.openoffice.org/issues/show_bug.cgi?id=70042http://www.openoffice.org/nonav/issues/showattachment.cgi/39509/alloc.overflows.wmf.patchhttp://www.redhat.com/support/errata/RHSA-2007-0001.htmlhttp://www.securityfocus.com/archive/1/455943/100/0/threadedhttp://www.securityfocus.com/archive/1/455947/100/0/threadedhttp://www.securityfocus.com/archive/1/455954/100/0/threadedhttp://www.securityfocus.com/archive/1/455964/100/0/threadedhttp://www.securityfocus.com/archive/1/456271/100/100/threadedhttp://www.ubuntu.com/usn/usn-406-1http://www.vupen.com/english/advisories/2007/0031http://www.vupen.com/english/advisories/2007/0059https://exchange.xforce.ibmcloud.com/vulnerabilities/31257https://issues.rpath.com/browse/RPL-905https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8280https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9145ftp://patches.sgi.com/support/free/security/advisories/20070101-01-P.aschttp://archives.neohapsis.com/archives/vulnwatch/2007-q1/0002.htmlyhttp://fedoranews.org/cms/node/2344http://lists.suse.com/archive/suse-security-announce/2007-Jan/0001.htmlhttp://osvdb.org/32610http://osvdb.org/32611http://secunia.com/advisories/23549http://secunia.com/advisories/23600http://secunia.com/advisories/23612http://secunia.com/advisories/23616http://secunia.com/advisories/23620http://secunia.com/advisories/23682http://secunia.com/advisories/23683http://secunia.com/advisories/23711http://secunia.com/advisories/23712http://secunia.com/advisories/23762http://secunia.com/advisories/23920http://security.gentoo.org/glsa/glsa-200701-07.xmlhttp://securitytracker.com/id?1017466http://sunsolve.sun.com/search/document.do?assetkey=1-26-102735-1http://www.debian.org/security/2007/dsa-1246http://www.kb.cert.org/vuls/id/220288http://www.mandriva.com/security/advisories?name=MDKSA-2007:006http://www.ngssoftware.com/advisories/high-risk-vulnerabilities-in-the-staroffice-suite/http://www.openoffice.org/issues/show_bug.cgi?id=70042http://www.openoffice.org/nonav/issues/showattachment.cgi/39509/alloc.overflows.wmf.patchhttp://www.redhat.com/support/errata/RHSA-2007-0001.htmlhttp://www.securityfocus.com/archive/1/455943/100/0/threadedhttp://www.securityfocus.com/archive/1/455947/100/0/threadedhttp://www.securityfocus.com/archive/1/455954/100/0/threadedhttp://www.securityfocus.com/archive/1/455964/100/0/threadedhttp://www.securityfocus.com/archive/1/456271/100/100/threadedhttp://www.ubuntu.com/usn/usn-406-1http://www.vupen.com/english/advisories/2007/0031http://www.vupen.com/english/advisories/2007/0059https://exchange.xforce.ibmcloud.com/vulnerabilities/31257https://issues.rpath.com/browse/RPL-905https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8280https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9145
2006-12-31
Published