An exploitable out-of-bounds write vulnerability exists in the read_MSAT function of libxls 1.4. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.debian.org/security/2018/dsa-4173 | third party advisory vendor advisory |
https://security.gentoo.org/glsa/202003-64 | third party advisory vendor advisory |
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0404 | third party advisory |