CVE-2006-5870: Buffer Overflow
Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of METAESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMRPOLYPOLYGON and (3) EMRPOLYPOLYGON16 records.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5870?
CVE-2006-5870 has a high severity rating due to its potential to allow remote code execution.
How do I fix CVE-2006-5870?
To fix CVE-2006-5870, users should update to OpenOffice.org version 2.1.0 or later, or apply any relevant patches provided by their software vendor.
What types of files are involved in CVE-2006-5870?
CVE-2006-5870 involves crafted WMF and EMF files that trigger integer overflows.
What versions of software are affected by CVE-2006-5870?
CVE-2006-5870 affects OpenOffice.org versions up to and including 2.0.4 and StarOffice 6 through 8.
Can CVE-2006-5870 be exploited by unauthenticated attackers?
CVE-2006-5870 generally requires user assistance, as the exploitation typically stems from opening malicious files.