PublicDate: 2006-06-30 18:05:00 UTC Candidate: CVE-2006-3117 References: https://ubuntu.com/security/notices/USN-313-1 https://ubuntu.com/security/notices/USN-313-2 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3117 Description: Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability." Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_openoffice.org-l10n: ignored (reached end-of-life) edgy_openoffice.org-l10n: released (2.0.4-0ubuntu1) feisty_openoffice.org-l10n: released (2.0.4-0ubuntu1) devel_openoffice.org-l10n: released (2.0.4-0ubuntu1) dapper_openoffice.org: released (2.0.2-2ubuntu12.4) edgy_openoffice.org: released (2.0.4-0ubuntu6) feisty_openoffice.org: released (2.2.0-1ubuntu4) dapper_openoffice.org-amd64: released (2.0.2-2ubuntu12.4-1) edgy_openoffice.org-amd64: DNE feisty_openoffice.org-amd64: DNE devel_openoffice.org-amd64: DNE upstream_openoffice.org: needs-triage upstream_openoffice.org-amd64: needs-triage upstream_openoffice.org-l10n: needs-triage