CVE-2006-5870

Publication date 31 December 2006

Last updated 24 July 2024


Ubuntu priority

Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.

Status

Package Ubuntu Release Status
openoffice.org 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Fixed 2.0.2-2ubuntu12.4
openoffice.org-amd64 7.04 feisty Not in release
6.10 edgy Not in release
6.06 LTS dapper
Fixed 2.0.2-2ubuntu12.4-1
openoffice.org-l10n 7.04 feisty
Fixed 2.2.0-0ubuntu2
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life

References

Related Ubuntu Security Notices (USN)

    • USN-406-1
    • OpenOffice.org vulnerability
    • 12 January 2007

Other references