6.8
CVSSv2

CVE-2017-2923

Published: 24/04/2018 Updated: 13/06/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freexl project freexl 1.0.3

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #875691 freexl: CVE-2017-2924: Heap-based buffer overflow in the read_legacy_biff function Package: src:freexl; Maintainer for src:freexl is Debian GIS Project <pkg-grass-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 13 Sep 2017 17:09:01 UTC ...
Debian Bug report logs - #875690 freexl: CVE-2017-2923: Heap-based buffer overflow in the read_biff_next_record function Package: src:freexl; Maintainer for src:freexl is Debian GIS Project <pkg-grass-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 13 Sep 2017 17:06:01 ...
Marcin Icewall Noga of Cisco Talos discovered two vulnerabilities in freexl, a library to read Microsoft Excel spreadsheets, which might result in denial of service or the execution of arbitrary code if a malformed Excel file is opened For the oldstable distribution (jessie), these problems have been fixed in version 100g-1+deb8u4 For the stabl ...