An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.debian.org/security/2018/dsa-4173 | third party advisory vendor advisory |
https://security.gentoo.org/glsa/202003-64 | third party advisory vendor advisory |
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0426 | third party advisory |