Vulnerabilities > CVE-2006-6628 - Remote Word File Integer Overflow vulnerability in Openoffice 2.1

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
openoffice
exploit available

Summary

Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted DOC file, as demonstrated by the 12122006-djtest.doc file, a variant of CVE-2006-6561 in a separate codebase.

Vulnerable Configurations

Part Description Count
Application
Openoffice
1

Exploit-Db

descriptionMicrosoft Word Document (malformed pointer) Proof of Concept. CVE-2006-6561,CVE-2006-6628. Dos exploit for windows platform
fileexploits/windows/dos/2922.txt
idEDB-ID:2922
last seen2016-01-31
modified2006-12-12
platformwindows
port
published2006-12-12
reporterDiscoJonny
sourcehttps://www.exploit-db.com/download/2922/
titleMicrosoft Word Document - malformed pointer Proof of Concept
typedos

Statements

contributorJoshua Bressers
lastmodified2007-01-15
organizationRed Hat
statementRed Hat does not consider this flaw a security issue. This flaw will only crash OpenOffice.org and presents no possibility for arbitrary code execution.