An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a arbitrary read resulting in memory disclosure. The vulnerability was confirmed on versions 11.3.0.2228 and 11.3.0.2400
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.talosintelligence.com/reports/TALOS-2017-0302/ | exploit vdb entry third party advisory |