Vulnerability Name: | CVE-2006-3493 (CCN-27617) | ||||||||
Assigned: | 2006-07-07 | ||||||||
Published: | 2006-07-07 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. Note: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees. | ||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P) 4.1 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
4.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Fri Jul 07 2006 - 16:02:39 CDT MS Word Unchecked Boundary Condition Vulnerability - POC Source: CCN Type: Microsoft Security Response Center Blog Monday, July 10, 2006 6:31 PM Information about claims about unchecked boundary condition vulnerability in Word Source: MISC Type: UNKNOWN http://blogs.technet.com/msrc/archive/2006/07/10/441006.aspx Source: MITRE Type: CNA CVE-2006-3493 Source: FULLDISC Type: UNKNOWN 20060707 MS Word Unchecked Boundary Condition Vulnerability - POC Source: FULLDISC Type: UNKNOWN 20060707 MS Word Unchecked Boundary Condition Source: FULLDISC Type: UNKNOWN 20060711 Fuzzing Microsoft Office Source: CCN Type: SECTRACK ID: 1016453 Microsoft Office LsCreateLine() Function May Let Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1016453 Source: CCN Type: OSVDB ID: 30820 Microsoft Word mso.dll / mso9.dll LsCreateLine Function DoS Source: BUGTRAQ Type: UNKNOWN 20060710 MS Word Unchecked Boundary Condition Vulnerability Source: BUGTRAQ Type: UNKNOWN 20060711 Fuzzing Microsoft Office Source: BID Type: Exploit 18905 Source: CCN Type: BID-18905 Microsoft Office MSO.DLL LsCreateLine() Potential Code Execution Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-2720 Source: XF Type: UNKNOWN office-lscreateline-dos(27617) Source: XF Type: UNKNOWN office-lscreateline-dos(27617) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |