CVE-2018-20452: Buffer Overflow
The readMSATbody function in ole.c in libxls 1.4.0 has an invalid free that allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, because of inconsistent memory management (new versus free) in ole2readheader in ole.c.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-20452?
CVE-2018-20452 is a vulnerability in libxls 1.4.0 that allows attackers to cause a denial of service or possibly have other impact via a crafted file.
How severe is CVE-2018-20452?
CVE-2018-20452 has a severity rating of 8.8 (high).
What is the affected software?
The affected software is Libxls Project Libxls version 1.4.0.
How can I fix CVE-2018-20452?
To fix CVE-2018-20452, users should update to a patched version of libxls.
Where can I find more information about CVE-2018-20452?
More information about CVE-2018-20452 can be found at the following references: [Reference 1](https://github.com/evanmiller/libxls/issues/35), [Reference 2](https://security.gentoo.org/glsa/202003-64).