CVE-2017-2924: Buffer Overflow
An exploitable heap-based buffer overflow vulnerability exists in the readlegacybiff function of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2924?
CVE-2017-2924 is classified as a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2017-2924?
To remediate CVE-2017-2924, upgrade FreeXL to version 1.0.4 or later.
What is the impact of CVE-2017-2924?
The impact of CVE-2017-2924 includes memory corruption leading to the possibility of remote code execution when a crafted XLS file is processed.
Which versions of FreeXL are affected by CVE-2017-2924?
FreeXL version 1.0.3 is impacted by CVE-2017-2924, with several patched versions available.
Who can exploit CVE-2017-2924?
An attacker can exploit CVE-2017-2924 by sending a specially crafted XLS file to the affected FreeXL application.