CVE-2006-5296: Medium severity Microsoft PowerPoint vulnerability

Published Oct 16, 2006
·
Updated

PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.

Affected Software

1 affected component
Microsoft PowerPoint=2003

Event History

Oct 16, 2006
CVE Published
07:07 PM
Data Sourced
via NVD·07:07 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2006-5296?

CVE-2006-5296 is classified as a denial of service vulnerability.

2

How do I fix CVE-2006-5296?

To fix CVE-2006-5296, Microsoft Office 2003 should be updated to the latest version to mitigate the risk.

3

What impact does CVE-2006-5296 have on my system?

CVE-2006-5296 can cause PowerPoint to crash, resulting in denial of service.

4

Which version of PowerPoint is affected by CVE-2006-5296?

CVE-2006-5296 affects Microsoft PowerPoint 2003.

5

Can CVE-2006-5296 be exploited remotely?

CVE-2006-5296 requires user interaction to exploit by opening a crafted PowerPoint file.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203