First published: Mon Nov 20 2017(Updated: )
An exploitable integer overflow vulnerability exists in the xls_appendSST function of libxls 1.4.A specially crafted XLS file can cause memory corruption resulting in remote code execution.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/r-cran-readxl | 1.3.0-1 1.3.1-2 1.4.2-1 1.4.3-1 | |
Libxls Project Libxls | =1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12110 is an integer overflow vulnerability in the xls_appendSST function of libxls 1.4.
CVE-2017-12110 has a severity value of 7.8, which is considered high.
CVE-2017-12110 can be exploited by a specially crafted XLS file to cause memory corruption and remote code execution.
Versions 1.3.0-1, 1.3.1-2, 1.4.2-1, and 1.4.3-1 of r-cran-readxl package in Debian and Libxls Project Libxls version 1.4 are affected by CVE-2017-12110.
To fix CVE-2017-12110, update to a version of r-cran-readxl package later than 1.4.3-1 or update Libxls Project Libxls to a version higher than 1.4.