First published: Wed Dec 02 2020(Updated: )
An exploitable Out-of-bounds Write vulnerability exists in the xls_addCell function of libxls 2.0. A specially crafted xls file can cause a memory corruption resulting in remote code execution. An attacker can send malicious xls file to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libxls Project Libxls | =2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2910 is an Out-of-bounds Write vulnerability in the xls_addCell function of libxls 2.0, which can result in remote code execution.
CVE-2017-2910 affects Libxls Project Libxls version 2.0.0.
The severity of CVE-2017-2910 is high with a CVSS score of 8.8.
CVE-2017-2910 can be exploited by sending a specially crafted xls file to trigger the vulnerability and cause memory corruption resulting in remote code execution.
At the time of this writing, there is no known fix available for CVE-2017-2910. It is recommended to follow the suggestions provided by the vendor or software developer to mitigate the risk.