6.5
CVSSv3

CVE-2018-20450

Published: 25/12/2018 Updated: 30/03/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The read_MSAT function in ole.c in libxls 1.4.0 has a double free that allows malicious users to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2017-2897.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libxls project libxls 1.4.0

Vendor Advisories

Debian Bug report logs - #919324 CVE-2018-20450 CVE-2018-20452 Package: r-cran-readxl; Maintainer for r-cran-readxl is Dirk Eddelbuettel <edd@debianorg>; Source for r-cran-readxl is src:r-cran-readxl (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 14 Jan 2019 22:36:01 UTC Severity: ...