CVE-2018-7437: High severity Freexl Project Freexl vulnerability
Published Feb 23, 2018
·Updated
An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a memcpy call of the parseSST function.
Affected Software
5 affected componentsFixes available
debian/freexl
1.0.5-31.0.6-11.0.6-22.0.0-1
Freexl Project Freexl<1.0.5
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/freexlto a version that resolves this vulnerability.Fixed in 1.0.5-3Fixed in 1.0.6-1Fixed in 1.0.6-2Fixed in 2.0.0-1
Event History
Feb 23, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7437?
CVE-2018-7437 has a severity rating of medium due to the potential for heap-based buffer over-read.
2
How do I fix CVE-2018-7437?
To fix CVE-2018-7437, upgrade FreeXL to version 1.0.5 or later.
3
What software is affected by CVE-2018-7437?
CVE-2018-7437 affects FreeXL versions prior to 1.0.5 as well as certain Debian distributions.
4
What are the specific versions vulnerable to CVE-2018-7437?
The vulnerable versions of FreeXL are all versions before 1.0.5.
5
Is CVE-2018-7437 related to any other vulnerabilities?
CVE-2018-7437 is primarily related to improper handling of memory in the parse_SST function.