CVE-2006-2198: High severity OpenOffice OpenOffice vulnerability
OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an OpenOffice document with a malicious BASIC macro, which is executed without prompting the user.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2198?
CVE-2006-2198 is considered a moderate severity vulnerability due to the potential for unauthorized actions through malicious BASIC macros in OpenOffice documents.
How do I fix CVE-2006-2198?
To mitigate CVE-2006-2198, users should upgrade to OpenOffice version 2.0.3 or later, which addresses the vulnerability.
Who is affected by CVE-2006-2198?
CVE-2006-2198 affects versions of OpenOffice 1.1.x up to 1.1.5 and 2.0.x prior to 2.0.3, as well as Sun StarOffice 7.0 and 8.0.
What type of attacks are possible with CVE-2006-2198?
CVE-2006-2198 allows attackers to execute unauthorized commands through user-assisted exploitation of malicious BASIC macros in documents.
Is user intervention required to exploit CVE-2006-2198?
Yes, user intervention is required as the attacker must persuade the user to open the malicious OpenOffice document for the exploit to take place.