Описание
An exploitable integer overflow vulnerability exists in the xls_preparseWorkSheet function of libxls 1.4 when handling a MULRK record. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | not-affected | 1.0.0-2 |
| cosmic | not-affected | 1.0.0-2 |
| devel | not-affected | 1.0.0-2 |
| disco | not-affected | 1.0.0-2 |
| eoan | not-affected | 1.0.0-2 |
| esm-apps/bionic | not-affected | 1.0.0-2 |
| esm-apps/focal | not-affected | 1.0.0-2 |
| esm-apps/jammy | not-affected | 1.0.0-2 |
| esm-apps/noble | not-affected | 1.0.0-2 |
Показывать по
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
An exploitable integer overflow vulnerability exists in the xls_preparseWorkSheet function of libxls 1.4 when handling a MULRK record. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
An exploitable integer overflow vulnerability exists in the xls_prepar ...
An exploitable integer overflow vulnerability exists in the xls_preparseWorkSheet function of libxls 1.4 when handling a MULRK record. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3