First published: Fri Jun 30 2006(Updated: )
Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to escape the Java sandbox and conduct unauthorized activities via certain applets in OpenOffice documents.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache OpenOffice | =2.0.0 | |
Apache OpenOffice | =1.1.1 | |
Apache OpenOffice | =1.1.2 | |
Apache OpenOffice | =1.1.4 | |
Libstaroffice | =6.0 | |
Libstaroffice | =7.0 | |
Apache OpenOffice | =1.1.0 | |
Libstaroffice | =8.0 | |
Apache OpenOffice | =2.0.1 | |
Apache OpenOffice | =1.1.3 | |
Apache OpenOffice | =1.1.5 | |
Apache OpenOffice | =2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2199 is considered a moderate severity vulnerability due to the potential for unauthorized actions facilitated by user interaction.
To fix CVE-2006-2199, update to OpenOffice.org version 2.0.3 or later, or apply any relevant patches from the vendor.
CVE-2006-2199 affects OpenOffice.org versions 1.1.x up to 1.1.5 and 2.0.x before 2.0.3.
No, users must be tricked into running malicious applets for CVE-2006-2199 to be exploited.
CVE-2006-2199 is classified as a Java sandbox escape vulnerability.