An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.debian.org/security/2017/dsa-3976 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/100799 | vdb entry broken link |
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0431 | third party advisory |