NA

CVE-2023-38854

Published: 15/08/2023 Updated: 19/08/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote malicious user to execute arbitrary code and cause a denial of service via a crafted XLS file to the transcode_latin1_to_utf8 function in xlstool.c:296.

Vulnerable Product Search on Vulmon Subscribe to Product

libxls project libxls 1.6.2

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: Buffer Overflow vulnerability in libxlsv162 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the transcode_latin1_to_utf8 function in xlstoolc:296 ...