Vulnerabilities > CVE-2006-5870 - Numeric Errors vulnerability in multiple products

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
openoffice
sun
CWE-189
critical
nessus

Summary

Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.

Vulnerable Configurations

Part Description Count
Application
Openoffice
1
Application
Sun
3

Common Weakness Enumeration (CWE)

Nessus

  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_120185.NASL
    descriptionStarOffice 8 (Solaris): Update 14. Date this patch was last updated by Sun : Sep/09/09
    last seen2018-09-02
    modified2018-08-22
    plugin id22960
    published2006-11-06
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=22960
    titleSolaris 5.10 (sparc) : 120185-19
    code
    #%NASL_MIN_LEVEL 80502
    
    # @DEPRECATED@
    #
    # This script has been deprecated as the associated patch is not
    # currently a recommended security fix.
    #
    # Disabled on 2011/09/17.
    
    #
    # (C) Tenable Network Security, Inc.
    #
    #
    
    if ( ! defined_func("bn_random") ) exit(0);
    include("compat.inc");
    
    if(description)
    {
     script_id(22960);
     script_version("1.33");
    
     script_name(english: "Solaris 5.10 (sparc) : 120185-19");
     script_cve_id("CVE-2006-2198", "CVE-2006-3117", "CVE-2006-5870", "CVE-2007-0002", "CVE-2007-0238", "CVE-2007-0239", "CVE-2007-0245", "CVE-2007-1466", "CVE-2007-2754", "CVE-2007-2834", "CVE-2007-4575");
     script_set_attribute(attribute: "synopsis", value:
    "The remote host is missing Sun Security Patch number 120185-19");
     script_set_attribute(attribute: "description", value:
    'StarOffice 8 (Solaris): Update 14.
    Date this patch was last updated by Sun : Sep/09/09');
     script_set_attribute(attribute: "solution", value:
    "You should install this patch for your system to be up-to-date.");
     script_set_attribute(attribute: "see_also", value:
    "https://getupdates.oracle.com/readme/120185-19");
     script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C");
     script_set_attribute(attribute:"exploitability_ease", value:"Exploits are available");
     script_set_attribute(attribute:"exploit_available", value:"true");
     script_set_attribute(attribute:"exploit_framework_canvas", value:"true");
     script_set_attribute(attribute:"canvas_package", value:'CANVAS');
     script_cwe_id(94);
     script_set_attribute(attribute:"plugin_publication_date", value: "2006/11/06");
     script_cvs_date("Date: 2019/10/25 13:36:23");
     script_set_attribute(attribute:"patch_publication_date", value: "2006/07/30");
     script_set_attribute(attribute:"vuln_publication_date", value: "2006/06/30");
     script_end_attributes();
    
     script_summary(english: "Check for patch 120185-19");
     script_category(ACT_GATHER_INFO);
     script_copyright(english:"This script is Copyright (C) 2006-2019 and is owned by Tenable, Inc. or an Affiliate thereof.");
     family["english"] = "Solaris Local Security Checks";
     script_family(english:family["english"]);
     
     script_dependencies("ssh_get_info.nasl");
     script_require_keys("Host/Solaris/showrev");
     exit(0);
    }
    
    
    
    # Deprecated.
    exit(0, "The associated patch is not currently a recommended security fix.");
    
  • NASL familyOracle Linux Local Security Checks
    NASL idORACLELINUX_ELSA-2007-0001.NASL
    descriptionFrom Red Hat Security Advisory 2007:0001 : Updated openoffice.org packages are now available. This update has been rated as having important security impact by the Red Hat Security Response Team. OpenOffice.org is an office productivity suite that includes desktop applications such as a word processor, spreadsheet, presentation manager, formula editor, and drawing program. Several integer overflow bugs were found in the OpenOffice.org WMF file processor. An attacker could create a carefully crafted WMF file that could cause OpenOffice.org to execute arbitrary code when the file was opened by a victim. (CVE-2006-5870) All users of OpenOffice.org are advised to upgrade to these updated packages, which contain a backported fix for this issue.
    last seen2020-06-01
    modified2020-06-02
    plugin id67433
    published2013-07-12
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/67433
    titleOracle Linux 4 : openoffice.org (ELSA-2007-0001)
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS9_X86_120190.NASL
    descriptionStarSuite 8 (Solaris_x86): Update 14. Date this patch was last updated by Sun : Sep/11/09
    last seen2016-09-26
    modified2011-09-18
    plugin id23617
    published2006-11-06
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=23617
    titleSolaris 5.9 (x86) : 120190-19
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS9_X86_120186.NASL
    descriptionStarOffice 8 (Solaris_x86): Update 14. Date this patch was last updated by Sun : Sep/10/09
    last seen2016-09-26
    modified2011-09-18
    plugin id23616
    published2006-11-06
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=23616
    titleSolaris 5.9 (x86) : 120186-19
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_X86_120186-23.NASL
    descriptionStarOffice 8 (Solaris_x86): Update 18. Date this patch was last updated by Sun : Mar/15/11
    last seen2020-06-01
    modified2020-06-02
    plugin id107857
    published2018-03-12
    reporterThis script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/107857
    titleSolaris 10 (x86) : 120186-23
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_120189.NASL
    descriptionStarSuite 8 (Solaris): Update 14. Date this patch was last updated by Sun : Sep/09/09
    last seen2018-09-02
    modified2018-08-22
    plugin id22961
    published2006-11-06
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=22961
    titleSolaris 5.10 (sparc) : 120189-19
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-1246.NASL
    descriptionJohn Heasman from Next Generation Security Software discovered a heap overflow in the handling of Windows Metafiles in OpenOffice.org, the free office suite, which could lead to a denial of service and potentially execution of arbitrary code.
    last seen2020-06-01
    modified2020-06-02
    plugin id24006
    published2007-01-11
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/24006
    titleDebian DSA-1246-1 : openoffice.org - buffer overflow
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_X86_120190-23.NASL
    descriptionStarSuite 8 (Solaris_x86): Update 18. Date this patch was last updated by Sun : Mar/15/11
    last seen2020-06-01
    modified2020-06-02
    plugin id107858
    published2018-03-12
    reporterThis script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/107858
    titleSolaris 10 (x86) : 120190-23
  • NASL familySuSE Local Security Checks
    NASL idSUSE_SA_2007_001.NASL
    descriptionThe remote host is missing the patch for the advisory SUSE-SA:2007:001 (OpenOffice_org). Security problems were fixed in the WMF and Enhanced WMF handling in OpenOffice_org These could potentially be used to execute code or crash OpenOffice when a user could be convinced to open specially crafted document (for instance a document sent by E-mail). This issue is tracked by the Mitre CVE ID CVE-2006-5870. openSUSE 10.2 is not affected by this problem, it already contains the fixed OpenOffice_org 2.1 version. Additionally the OpenOffice_org 2.0 version in SLED 10 was fitted with hooks to add OfficeXML support with a later update. Due to the very large size of this update and mirror lag it might take some hours or days until the updates are available on our mirrors.
    last seen2019-10-28
    modified2007-02-18
    plugin id24456
    published2007-02-18
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/24456
    titleSUSE-SA:2007:001: OpenOffice_org
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS9_120189.NASL
    descriptionStarSuite 8 (Solaris): Update 14. Date this patch was last updated by Sun : Sep/09/09
    last seen2016-09-26
    modified2011-09-18
    plugin id23558
    published2006-11-06
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=23558
    titleSolaris 5.9 (sparc) : 120189-19
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_120189-23.NASL
    descriptionStarSuite 8 (Solaris): Update 18. Date this patch was last updated by Sun : Mar/15/11
    last seen2020-06-01
    modified2020-06-02
    plugin id107356
    published2018-03-12
    reporterThis script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/107356
    titleSolaris 10 (sparc) : 120189-23
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_X86_120190.NASL
    descriptionStarSuite 8 (Solaris_x86): Update 14. Date this patch was last updated by Sun : Sep/11/09
    last seen2018-09-01
    modified2018-08-22
    plugin id22994
    published2006-11-06
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=22994
    titleSolaris 5.10 (x86) : 120190-19
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS8_120189.NASL
    descriptionStarSuite 8 (Solaris): Update 14. Date this patch was last updated by Sun : Sep/09/09
    last seen2016-09-26
    modified2011-09-18
    plugin id23420
    published2006-11-06
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=23420
    titleSolaris 5.8 (sparc) : 120189-19
  • NASL familySuSE Local Security Checks
    NASL idSUSE_OPENOFFICE_ORG-2407.NASL
    descriptionFollowing security problem was fixed in OpenOffice_org : - Bufferoverflows in WMF and Enhanced WMF handling in OpenOffice_org could be used to potentially execute code or crash OpenOffice_org. It is necessary that the user can be tricked to open a prepared document. (CVE-2006-5870) This update also adds code to later hook in the OfficeXML converter (odf-converter.sf.net).
    last seen2020-06-01
    modified2020-06-02
    plugin id29364
    published2007-12-13
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/29364
    titleSuSE 10 Security Update : OpenOffice_org (ZYPP Patch Number 2407)
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200701-07.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200701-07 (OpenOffice.org: EMF/WMF file handling vulnerabilities) John Heasman of NGSSoftware has discovered integer overflows in the EMR_POLYPOLYGON and EMR_POLYPOLYGON16 processing and an error within the handling of META_ESCAPE records. Impact : An attacker could exploit these vulnerabilities to cause heap overflows and potentially execute arbitrary code with the privileges of the user running OpenOffice.org by enticing the user to open a document containing a malicious WMF/EMF file. Workaround : There is no known workaround known at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id24205
    published2007-01-17
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/24205
    titleGLSA-200701-07 : OpenOffice.org: EMF/WMF file handling vulnerabilities
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS8_120185.NASL
    descriptionStarOffice 8 (Solaris): Update 14. Date this patch was last updated by Sun : Sep/09/09
    last seen2016-09-26
    modified2011-09-18
    plugin id23419
    published2006-11-06
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=23419
    titleSolaris 5.8 (sparc) : 120185-19
  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2007-0001.NASL
    descriptionUpdated openoffice.org packages are now available. This update has been rated as having important security impact by the Red Hat Security Response Team. OpenOffice.org is an office productivity suite that includes desktop applications such as a word processor, spreadsheet, presentation manager, formula editor, and drawing program. Several integer overflow bugs were found in the OpenOffice.org WMF file processor. An attacker could create a carefully crafted WMF file that could cause OpenOffice.org to execute arbitrary code when the file was opened by a victim. (CVE-2006-5870) All users of OpenOffice.org are advised to upgrade to these updated packages, which contain a backported fix for this issue.
    last seen2020-06-01
    modified2020-06-02
    plugin id23993
    published2007-01-08
    reporterThis script is Copyright (C) 2007-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/23993
    titleRHEL 3 / 4 : openoffice.org (RHSA-2007:0001)
  • NASL familyUbuntu Local Security Checks
    NASL idUBUNTU_USN-406-1.NASL
    descriptionAn integer overflow was discovered in OpenOffice.org
    last seen2020-06-01
    modified2020-06-02
    plugin id27994
    published2007-11-10
    reporterUbuntu Security Notice (C) 2007-2019 Canonical, Inc. / NASL script (C) 2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/27994
    titleUbuntu 5.10 / 6.06 LTS : openoffice.org/-amd64, openoffice.org2/-amd64 vulnerability (USN-406-1)
  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2007-006.NASL
    descriptionSeveral integer overflows were discovered in the OpenOffice.org WMF file processor. An attacker could create a carefully crafted WMF file that would cause OpenOffice.org to execute arbitrary code when opened. Updated packages are patched to address this issue.
    last seen2020-06-01
    modified2020-06-02
    plugin id24622
    published2007-02-18
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/24622
    titleMandrake Linux Security Advisory : openoffice.org (MDKSA-2007:006)
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_X86_120186.NASL
    descriptionStarOffice 8 (Solaris_x86): Update 14. Date this patch was last updated by Sun : Sep/10/09
    last seen2018-09-01
    modified2018-08-22
    plugin id22993
    published2006-11-06
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=22993
    titleSolaris 5.10 (x86) : 120186-19
  • NASL familySuSE Local Security Checks
    NASL idSUSE_OPENOFFICE_ORG-2408.NASL
    descriptionFollowing security problem was fixed in OpenOffice_org : CVE-2006-5870: Bufferoverflows in WMF and Enhanced WMF handling in OpenOffice_org could be used to potentially execute code or crash OpenOffice_org. It is necessary that the user can be tricked to open a prepared document. This update also adds code to later hook in the OfficeXML converter (odf-converter.sf.net).
    last seen2020-06-01
    modified2020-06-02
    plugin id27135
    published2007-10-17
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/27135
    titleopenSUSE 10 Security Update : OpenOffice_org (OpenOffice_org-2408)
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_120185-23.NASL
    descriptionStarOffice 8 (Solaris): Update 18. Date this patch was last updated by Sun : Mar/15/11
    last seen2020-06-01
    modified2020-06-02
    plugin id107355
    published2018-03-12
    reporterThis script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/107355
    titleSolaris 10 (sparc) : 120185-23
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2007-005.NASL
    descriptionRectifies an error patch condition where by corrupt wmf/emf files with out of bounds values in the emf/wmf file could enable an attacker by constructing a malicious file to execute arbitrary code if opened in OpenOffice by a victim. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id24184
    published2007-01-17
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/24184
    titleFedora Core 5 : openoffice.org-2.0.2-5.20.2 / Fedora Core 6 : openoffice.org-2.0.4-5.5.10 (2007-005)
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS9_120185.NASL
    descriptionStarOffice 8 (Solaris): Update 14. Date this patch was last updated by Sun : Sep/09/09
    last seen2016-09-26
    modified2011-09-18
    plugin id23557
    published2006-11-06
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=23557
    titleSolaris 5.9 (sparc) : 120185-19
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS8_X86_120186.NASL
    descriptionStarOffice 8 (Solaris_x86): Update 14. Date this patch was last updated by Sun : Sep/10/09
    last seen2016-09-26
    modified2011-09-18
    plugin id23467
    published2006-11-06
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=23467
    titleSolaris 5.8 (x86) : 120186-19
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS8_X86_120190.NASL
    descriptionStarSuite 8 (Solaris_x86): Update 14. Date this patch was last updated by Sun : Sep/11/09
    last seen2016-09-26
    modified2011-09-18
    plugin id23468
    published2006-11-06
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=23468
    titleSolaris 5.8 (x86) : 120190-19
  • NASL familyCentOS Local Security Checks
    NASL idCENTOS_RHSA-2007-0001.NASL
    descriptionUpdated openoffice.org packages are now available. This update has been rated as having important security impact by the Red Hat Security Response Team. OpenOffice.org is an office productivity suite that includes desktop applications such as a word processor, spreadsheet, presentation manager, formula editor, and drawing program. Several integer overflow bugs were found in the OpenOffice.org WMF file processor. An attacker could create a carefully crafted WMF file that could cause OpenOffice.org to execute arbitrary code when the file was opened by a victim. (CVE-2006-5870) All users of OpenOffice.org are advised to upgrade to these updated packages, which contain a backported fix for this issue.
    last seen2020-06-01
    modified2020-06-02
    plugin id23984
    published2007-01-08
    reporterThis script is Copyright (C) 2007-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/23984
    titleCentOS 3 / 4 : openoffice.org (CESA-2007:0001)

Oval

  • accepted2014-06-09T04:01:48.851-04:00
    classvulnerability
    contributors
    • nameThomas R. Jones
      organizationMaitreya Security
    • nameJonathan Baker
      organizationThe MITRE Corporation
    • nameJonathan Baker
      organizationThe MITRE Corporation
    • nameJerome Athias
      organizationMcAfee, Inc.
    definition_extensions
    • commentNovell Linux Desktop 9 is installed
      ovaloval:org.mitre.oval:def:2090
    • commentSUSE Linux Desktop 1.0 is installed
      ovaloval:org.mitre.oval:def:1366
    • commentSUSE Linux 10.1 is installed
      ovaloval:org.mitre.oval:def:2157
    • commentPackage OpenOffice_org is installed
      ovaloval:org.mitre.oval:def:8865
    • commentPackage OpenOffice_org-gnome is installed
      ovaloval:org.mitre.oval:def:8914
    • commentPackage OpenOffice_org-kde is installed
      ovaloval:org.mitre.oval:def:9199
    • commentPackage OpenOffice_org-mono is installed
      ovaloval:org.mitre.oval:def:8222
    • commentPackage OpenOffice_org-officebean is installed
      ovaloval:org.mitre.oval:def:8541
    • commentSUSE Linux 10.0 is installed
      ovaloval:org.mitre.oval:def:2027
    • commentPackage OpenOffice_org is installed
      ovaloval:org.mitre.oval:def:8865
    • commentPackage OpenOffice_org-af is installed
      ovaloval:org.mitre.oval:def:8974
    • commentPackage OpenOffice_org-ar is installed
      ovaloval:org.mitre.oval:def:8663
    • commentPackage OpenOffice_org-be-BY is installed
      ovaloval:org.mitre.oval:def:8432
    • commentPackage OpenOffice_org-bg is installed
      ovaloval:org.mitre.oval:def:8403
    • commentPackage OpenOffice_org-ca is installed
      ovaloval:org.mitre.oval:def:8887
    • commentPackage OpenOffice_org-cs is installed
      ovaloval:org.mitre.oval:def:8733
    • commentPackage OpenOffice_org-cy is installed
      ovaloval:org.mitre.oval:def:8329
    • commentPackage OpenOffice_org-da is installed
      ovaloval:org.mitre.oval:def:8998
    • commentPackage OpenOffice_org-de is installed
      ovaloval:org.mitre.oval:def:8688
    • commentPackage OpenOffice_org-el is installed
      ovaloval:org.mitre.oval:def:8801
    • commentPackage OpenOffice_org-en-GB is installed
      ovaloval:org.mitre.oval:def:8829
    • commentPackage OpenOffice_org-es is installed
      ovaloval:org.mitre.oval:def:8583
    • commentPackage OpenOffice_org-et is installed
      ovaloval:org.mitre.oval:def:8678
    • commentPackage OpenOffice_org-fi is installed
      ovaloval:org.mitre.oval:def:8451
    • commentPackage OpenOffice_org-fr is installed
      ovaloval:org.mitre.oval:def:8215
    • commentPackage OpenOffice_org-galleries is installed
      ovaloval:org.mitre.oval:def:8997
    • commentPackage OpenOffice_org-gnome is installed
      ovaloval:org.mitre.oval:def:8914
    • commentPackage OpenOffice_org-gu-IN is installed
      ovaloval:org.mitre.oval:def:8341
    • commentPackage OpenOffice_org-hr is installed
      ovaloval:org.mitre.oval:def:8715
    • commentPackage OpenOffice_org-hu is installed
      ovaloval:org.mitre.oval:def:8228
    • commentPackage OpenOffice_org-hunspell is installed
      ovaloval:org.mitre.oval:def:8892
    • commentPackage OpenOffice_org-it is installed
      ovaloval:org.mitre.oval:def:9104
    • commentPackage OpenOffice_org-ja is installed
      ovaloval:org.mitre.oval:def:8987
    • commentPackage OpenOffice_org-kde is installed
      ovaloval:org.mitre.oval:def:9199
    • commentPackage OpenOffice_org-ko is installed
      ovaloval:org.mitre.oval:def:8352
    • commentPackage OpenOffice_org-mono is installed
      ovaloval:org.mitre.oval:def:8222
    • commentPackage OpenOffice_org-nb is installed
      ovaloval:org.mitre.oval:def:8804
    • commentPackage OpenOffice_org-nl is installed
      ovaloval:org.mitre.oval:def:8611
    • commentPackage OpenOffice_org-nn is installed
      ovaloval:org.mitre.oval:def:8501
    • commentPackage OpenOffice_org-officebean is installed
      ovaloval:org.mitre.oval:def:8541
    • commentPackage OpenOffice_org-pa-IN is installed
      ovaloval:org.mitre.oval:def:8882
    • commentPackage OpenOffice_org-pl is installed
      ovaloval:org.mitre.oval:def:8799
    • commentPackage OpenOffice_org-pt is installed
      ovaloval:org.mitre.oval:def:8664
    • commentPackage OpenOffice_org-pt-BR is installed
      ovaloval:org.mitre.oval:def:8886
    • commentPackage OpenOffice_org-ru is installed
      ovaloval:org.mitre.oval:def:8389
    • commentPackage OpenOffice_org-sk is installed
      ovaloval:org.mitre.oval:def:8244
    • commentPackage OpenOffice_org-sl is installed
      ovaloval:org.mitre.oval:def:9181
    • commentPackage OpenOffice_org-sv is installed
      ovaloval:org.mitre.oval:def:8860
    • commentPackage OpenOffice_org-tr is installed
      ovaloval:org.mitre.oval:def:8707
    • commentPackage OpenOffice_org-vi is installed
      ovaloval:org.mitre.oval:def:8288
    • commentPackage OpenOffice_org-xh is installed
      ovaloval:org.mitre.oval:def:8477
    • commentPackage OpenOffice_org-zh-CN is installed
      ovaloval:org.mitre.oval:def:8995
    • commentPackage OpenOffice_org-zh-TW is installed
      ovaloval:org.mitre.oval:def:9146
    • commentPackage OpenOffice_org-zu is installed
      ovaloval:org.mitre.oval:def:8269
    • commentSUSE Linux Professional 9.3 is installed
      ovaloval:org.mitre.oval:def:2044
    • commentPackage OpenOffice_org1 is installed
      ovaloval:org.mitre.oval:def:8264
    • commentPackage OpenOffice_org1-ar is installed
      ovaloval:org.mitre.oval:def:8777
    • commentPackage OpenOffice_org1-ca is installed
      ovaloval:org.mitre.oval:def:8915
    • commentPackage OpenOffice_org1-cs is installed
      ovaloval:org.mitre.oval:def:8357
    • commentPackage OpenOffice_org1-da is installed
      ovaloval:org.mitre.oval:def:8308
    • commentPackage OpenOffice_org1-de is installed
      ovaloval:org.mitre.oval:def:8533
    • commentPackage OpenOffice_org1-el is installed
      ovaloval:org.mitre.oval:def:8652
    • commentPackage OpenOffice_org1-en is installed
      ovaloval:org.mitre.oval:def:8958
    • commentPackage OpenOffice_org1-es is installed
      ovaloval:org.mitre.oval:def:8705
    • commentPackage OpenOffice_org1-et is installed
      ovaloval:org.mitre.oval:def:8681
    • commentPackage OpenOffice_org1-fi is installed
      ovaloval:org.mitre.oval:def:8815
    • commentPackage OpenOffice_org1-fr is installed
      ovaloval:org.mitre.oval:def:8672
    • commentPackage OpenOffice_org1-gnome is installed
      ovaloval:org.mitre.oval:def:8342
    • commentPackage OpenOffice_org1-hu is installed
      ovaloval:org.mitre.oval:def:8380
    • commentPackage OpenOffice_org1-it is installed
      ovaloval:org.mitre.oval:def:8691
    • commentPackage OpenOffice_org1-ja is installed
      ovaloval:org.mitre.oval:def:9174
    • commentPackage OpenOffice_org1-kde is installed
      ovaloval:org.mitre.oval:def:8774
    • commentPackage OpenOffice_org1-ko is installed
      ovaloval:org.mitre.oval:def:9070
    • commentPackage OpenOffice_org1-nl is installed
      ovaloval:org.mitre.oval:def:9192
    • commentPackage OpenOffice_org1-pl is installed
      ovaloval:org.mitre.oval:def:8502
    • commentPackage OpenOffice_org1-pt is installed
      ovaloval:org.mitre.oval:def:8906
    • commentPackage OpenOffice_org1-ru is installed
      ovaloval:org.mitre.oval:def:9169
    • commentPackage OpenOffice_org1-sk is installed
      ovaloval:org.mitre.oval:def:8903
    • commentPackage OpenOffice_org1-sl is installed
      ovaloval:org.mitre.oval:def:8773
    • commentPackage OpenOffice_org1-sv is installed
      ovaloval:org.mitre.oval:def:9168
    • commentPackage OpenOffice_org1-tr is installed
      ovaloval:org.mitre.oval:def:8310
    • commentPackage OpenOffice_org1-zh-CN is installed
      ovaloval:org.mitre.oval:def:8604
    • commentPackage OpenOffice_org1-zh-TW is installed
      ovaloval:org.mitre.oval:def:8999
    • commentSUSE Linux Enterprise Desktop 10 is installed
      ovaloval:org.mitre.oval:def:2106
    descriptionMultiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.
    familyunix
    idoval:org.mitre.oval:def:8280
    statusaccepted
    submitted2007-07-22T11:38:47
    titleOpenOffice_org WMF buffer overflows
    version39
  • accepted2013-04-29T04:18:19.805-04:00
    classvulnerability
    contributors
    • nameAharon Chernin
      organizationSCAP.com, LLC
    • nameDragos Prisaca
      organizationG2, Inc.
    definition_extensions
    • commentThe operating system installed on the system is Red Hat Enterprise Linux 3
      ovaloval:org.mitre.oval:def:11782
    • commentCentOS Linux 3.x
      ovaloval:org.mitre.oval:def:16651
    • commentThe operating system installed on the system is Red Hat Enterprise Linux 4
      ovaloval:org.mitre.oval:def:11831
    • commentCentOS Linux 4.x
      ovaloval:org.mitre.oval:def:16636
    • commentOracle Linux 4.x
      ovaloval:org.mitre.oval:def:15990
    descriptionMultiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.
    familyunix
    idoval:org.mitre.oval:def:9145
    statusaccepted
    submitted2010-07-09T03:56:16-04:00
    titleMultiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.
    version26

Redhat

advisories
bugzilla
id217347
titleCVE-2006-5870 WMF heap overflow
oval
OR
  • commentRed Hat Enterprise Linux must be installed
    ovaloval:com.redhat.rhba:tst:20070304026
  • AND
    • commentRed Hat Enterprise Linux 4 is installed
      ovaloval:com.redhat.rhba:tst:20070304025
    • OR
      • AND
        • commentopenoffice.org is earlier than 0:1.1.5-6.6.0.EL4
          ovaloval:com.redhat.rhsa:tst:20070001001
        • commentopenoffice.org is signed with Red Hat master key
          ovaloval:com.redhat.rhsa:tst:20060573002
      • AND
        • commentopenoffice.org-libs is earlier than 0:1.1.5-6.6.0.EL4
          ovaloval:com.redhat.rhsa:tst:20070001003
        • commentopenoffice.org-libs is signed with Red Hat master key
          ovaloval:com.redhat.rhsa:tst:20060573008
      • AND
        • commentopenoffice.org-kde is earlier than 0:1.1.5-6.6.0.EL4
          ovaloval:com.redhat.rhsa:tst:20070001005
        • commentopenoffice.org-kde is signed with Red Hat master key
          ovaloval:com.redhat.rhsa:tst:20060573006
      • AND
        • commentopenoffice.org-i18n is earlier than 0:1.1.5-6.6.0.EL4
          ovaloval:com.redhat.rhsa:tst:20070001007
        • commentopenoffice.org-i18n is signed with Red Hat master key
          ovaloval:com.redhat.rhsa:tst:20060573004
rhsa
idRHSA-2007:0001
released2007-01-03
severityImportant
titleRHSA-2007:0001: openoffice.org security update (Important)
rpms
  • openoffice.org-0:1.1.2-35.2.0.EL3
  • openoffice.org-0:1.1.5-6.6.0.EL4
  • openoffice.org-debuginfo-0:1.1.2-35.2.0.EL3
  • openoffice.org-debuginfo-0:1.1.5-6.6.0.EL4
  • openoffice.org-i18n-0:1.1.2-35.2.0.EL3
  • openoffice.org-i18n-0:1.1.5-6.6.0.EL4
  • openoffice.org-kde-0:1.1.5-6.6.0.EL4
  • openoffice.org-libs-0:1.1.2-35.2.0.EL3
  • openoffice.org-libs-0:1.1.5-6.6.0.EL4

Statements

contributorMark J Cox
lastmodified2007-03-14
organizationRed Hat
statementRed Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

References