CVE-2018-7436: High severity Freexl Project Freexl vulnerability
Published Feb 23, 2018
·Updated
An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the parseSST function.
Affected Software
5 affected componentsFixes available
debian/freexl
1.0.5-31.0.6-11.0.6-22.0.0-1
Freexl Project Freexl<1.0.5
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/freexlto a version that resolves this vulnerability.Fixed in 1.0.5-3Fixed in 1.0.6-1Fixed in 1.0.6-2Fixed in 2.0.0-1
Event History
Feb 23, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7436?
CVE-2018-7436 has been classified as having medium severity due to the potential for a heap-based buffer over-read.
2
How do I fix CVE-2018-7436?
To fix CVE-2018-7436, upgrade to FreeXL version 1.0.5 or later.
3
Which software is affected by CVE-2018-7436?
CVE-2018-7436 affects FreeXL versions before 1.0.5 across various Debian distributions.
4
What type of vulnerability is CVE-2018-7436?
CVE-2018-7436 is a heap-based buffer over-read vulnerability.
5
Can CVE-2018-7436 be exploited remotely?
Yes, CVE-2018-7436 can be exploited remotely if the affected software is accessible.