First published: Mon Nov 20 2017(Updated: )
An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1.4. . A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libxls Project Libxls | =1.4 | |
Debian Debian Linux | =10.0 | |
debian/r-cran-readxl | 1.3.0-1 1.3.1-2 1.4.2-1 1.4.3-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-2896 is high, with a CVSS score of 7.8.
CVE-2017-2896 affects libxls versions 1.4 and can cause a memory corruption resulting in remote code execution.
To fix CVE-2017-2896 in the r-cran-readxl package (Debian), update to version 1.4.2-1 or later.
To mitigate CVE-2017-2896 in Libxls Project Libxls, update to version 1.4 or later.
Yes, you can find additional information about CVE-2017-2896 at the following references: [link1](https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0403), [link2](https://security-tracker.debian.org/tracker/CVE-2017-2896), [link3](https://security.gentoo.org/glsa/202003-64).