6.8
CVSSv2

CVE-2018-20452

Published: 25/12/2018 Updated: 30/03/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The read_MSAT_body function in ole.c in libxls 1.4.0 has an invalid free that allows malicious users to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, because of inconsistent memory management (new versus free) in ole2_read_header in ole.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libxls project libxls 1.4.0

Vendor Advisories

Debian Bug report logs - #919324 CVE-2018-20450 CVE-2018-20452 Package: r-cran-readxl; Maintainer for r-cran-readxl is Dirk Eddelbuettel <edd@debianorg>; Source for r-cran-readxl is src:r-cran-readxl (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 14 Jan 2019 22:36:01 UTC Severity: ...