CVE-2017-2910: High severity Libxls Project Libxls vulnerability
An exploitable Out-of-bounds Write vulnerability exists in the xlsaddCell function of libxls 2.0. A specially crafted xls file can cause a memory corruption resulting in remote code execution. An attacker can send malicious xls file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-2910?
CVE-2017-2910 is an Out-of-bounds Write vulnerability in the xls_addCell function of libxls 2.0, which can result in remote code execution.
How does CVE-2017-2910 affect Libxls Project Libxls?
CVE-2017-2910 affects Libxls Project Libxls version 2.0.0.
What is the severity of CVE-2017-2910?
The severity of CVE-2017-2910 is high with a CVSS score of 8.8.
How can CVE-2017-2910 be exploited?
CVE-2017-2910 can be exploited by sending a specially crafted xls file to trigger the vulnerability and cause memory corruption resulting in remote code execution.
Is there a fix available for CVE-2017-2910?
At the time of this writing, there is no known fix available for CVE-2017-2910. It is recommended to follow the suggestions provided by the vendor or software developer to mitigate the risk.