Vulnerability Name:

CVE-2006-3493 (CCN-27617)

Assigned:2006-07-07
Published:2006-07-07
Updated:2018-10-30
Summary:Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type.
Note: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.
CVSS v3 Severity:5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
4.1 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
4.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Denial of Service
References:Source: CCN
Type: Full-Disclosure Mailing List, Fri Jul 07 2006 - 16:02:39 CDT
MS Word Unchecked Boundary Condition Vulnerability - POC

Source: CCN
Type: Microsoft Security Response Center Blog Monday, July 10, 2006 6:31 PM
Information about claims about unchecked boundary condition vulnerability in Word

Source: MISC
Type: UNKNOWN
http://blogs.technet.com/msrc/archive/2006/07/10/441006.aspx

Source: MITRE
Type: CNA
CVE-2006-3493

Source: FULLDISC
Type: UNKNOWN
20060707 MS Word Unchecked Boundary Condition Vulnerability - POC

Source: FULLDISC
Type: UNKNOWN
20060707 MS Word Unchecked Boundary Condition

Source: FULLDISC
Type: UNKNOWN
20060711 Fuzzing Microsoft Office

Source: CCN
Type: SECTRACK ID: 1016453
Microsoft Office LsCreateLine() Function May Let Remote Users Execute Arbitrary Code

Source: SECTRACK
Type: UNKNOWN
1016453

Source: CCN
Type: OSVDB ID: 30820
Microsoft Word mso.dll / mso9.dll LsCreateLine Function DoS

Source: BUGTRAQ
Type: UNKNOWN
20060710 MS Word Unchecked Boundary Condition Vulnerability

Source: BUGTRAQ
Type: UNKNOWN
20060711 Fuzzing Microsoft Office

Source: BID
Type: Exploit
18905

Source: CCN
Type: BID-18905
Microsoft Office MSO.DLL LsCreateLine() Potential Code Execution Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2006-2720

Source: XF
Type: UNKNOWN
office-lscreateline-dos(27617)

Source: XF
Type: UNKNOWN
office-lscreateline-dos(27617)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:office:2000:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2000:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2000:sp2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2000:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2003:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2003:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2003:sp2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2003:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:xp:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:xp:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:xp:sp2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:xp:sp3:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:office:2000:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2003:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2002:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft office 2000
    microsoft office 2000 sp1
    microsoft office 2000 sp2
    microsoft office 2000 sp3
    microsoft office 2003
    microsoft office 2003 sp1
    microsoft office 2003 sp2
    microsoft office 2003 sp3
    microsoft office xp
    microsoft office xp sp1
    microsoft office xp sp2
    microsoft office xp sp3
    microsoft office 2000
    microsoft office 2003
    microsoft office 2002