6.8
CVSSv2

CVE-2018-7437

Published: 23/02/2018 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in FreeXL prior to 1.0.5. There is a heap-based buffer over-read in a memcpy call of the parse_SST function.

Vulnerable Product Search on Vulmon Subscribe to Product

freexl project freexl

debian debian linux 8.0

debian debian linux 7.0

debian debian linux 9.0

Vendor Advisories

Multiple heap buffer over reads were discovered in freexl, a library to read Microsoft Excel spreadsheets, which could result in denial of service For the oldstable distribution (jessie), these problems have been fixed in version 100g-1+deb8u5 For the stable distribution (stretch), these problems have been fixed in version 102-2+deb9u2 We re ...