PT-2006-4368 · Microsoft · Office Word+1
Kcope
·
Published
2006-07-10
·
Updated
2018-10-30
·
CVE-2006-3493
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Office versions prior to the fixed version
Description
A buffer overflow issue exists in the LsCreateLine function, affecting Microsoft Word and possibly other products in Microsoft Office. This issue can be exploited by remote user-assisted attackers via a crafted Word DOC or other Office file type, leading to a denial of service (crash). Initially, it was reported that this issue could allow code execution, but Microsoft and the original researcher later confirmed that code execution is not possible.
Recommendations
For Microsoft Office versions prior to the fixed version, update to the fixed version to resolve the issue. As a temporary workaround, consider avoiding the use of crafted Word DOC or other Office file types that could trigger the buffer overflow in the LsCreateLine function.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Office
Office Word