CVE-2006-5296: Medium severity Microsoft PowerPoint vulnerability
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5296?
CVE-2006-5296 is classified as a denial of service vulnerability.
How do I fix CVE-2006-5296?
To fix CVE-2006-5296, Microsoft Office 2003 should be updated to the latest version to mitigate the risk.
What impact does CVE-2006-5296 have on my system?
CVE-2006-5296 can cause PowerPoint to crash, resulting in denial of service.
Which version of PowerPoint is affected by CVE-2006-5296?
CVE-2006-5296 affects Microsoft PowerPoint 2003.
Can CVE-2006-5296 be exploited remotely?
CVE-2006-5296 requires user interaction to exploit by opening a crafted PowerPoint file.