CVE-2008-0668: Integer Overflow
The excelreadHLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file containing XLS HLINK opcodes, possibly because of an integer signedness error that leads to an integer overflow. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0668?
CVE-2008-0668 is considered a high severity vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2008-0668?
To fix CVE-2008-0668, update Gnumeric to version 1.8.1 or later.
Who is affected by CVE-2008-0668?
CVE-2008-0668 affects users of Gnome Office Gnumeric versions up to and including 1.7.91.
What type of attack does CVE-2008-0668 enable?
CVE-2008-0668 enables user-assisted remote attackers to execute arbitrary code via a specially crafted XLS file.
When was CVE-2008-0668 disclosed?
CVE-2008-0668 was disclosed in February 2008.