CVE-2017-2923: Buffer Overflow
An exploitable heap based buffer overflow vulnerability exists in the 'readbiffnextrecord function' of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
Other sources
An exploitable heap based buffer overflow vulnerability exists in the readbiffnextrecord function of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
External References:
https://www.talosintelligence.com/vulnerabilityreports/TALOS-2017-0430
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2923?
CVE-2017-2923 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2017-2923?
To remediate CVE-2017-2923, upgrade FreeXL to version 1.0.4 or later.
What software is affected by CVE-2017-2923?
CVE-2017-2923 affects FreeXL versions up to and including 1.0.3.
Can CVE-2017-2923 be exploited remotely?
Yes, an attacker can exploit CVE-2017-2923 remotely by sending a specially crafted XLS file.
What impact can CVE-2017-2923 have on my system?
CVE-2017-2923 can lead to memory corruption and potential remote code execution on vulnerable systems.