7.5
CVSSv2

CVE-2006-4514

Published: 30/11/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the ole_info_read_metabat function in Gnome Structured File library (libgsf) 1.14.0, and other versions prior to 1.14.2, allows context-dependent malicious users to execute arbitrary code via a large num_metabat value in an OLE document, which causes the ole_init_info function to allocate insufficient memory.

Vulnerable Product Search on Vulmon Subscribe to Product

libgsf libgsf 1.13.2

libgsf libgsf 1.14

libgsf libgsf 1.11.1

libgsf libgsf 1.14.1

Vendor Advisories

A heap overflow was discovered in the OLE processing code in libgsf If a user were tricked into opening a specially crafted OLE document, an attacker could execute arbitrary code with the user’s privileges ...