First published: Tue Dec 25 2018(Updated: )
The read_MSAT_body function in ole.c in libxls 1.4.0 has an invalid free that allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, because of inconsistent memory management (new versus free) in ole2_read_header in ole.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libxls Project Libxls | =1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20452 is a vulnerability in libxls 1.4.0 that allows attackers to cause a denial of service or possibly have other impact via a crafted file.
CVE-2018-20452 has a severity rating of 8.8 (high).
The affected software is Libxls Project Libxls version 1.4.0.
To fix CVE-2018-20452, users should update to a patched version of libxls.
More information about CVE-2018-20452 can be found at the following references: [Reference 1](https://github.com/evanmiller/libxls/issues/35), [Reference 2](https://security.gentoo.org/glsa/202003-64).