CVE-2018-7439: High severity Freexl Project Freexl vulnerability
Published Feb 23, 2018
·Updated
An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the function readminibiffnextrecord.
Affected Software
5 affected componentsFixes available
debian/freexl
1.0.5-31.0.6-11.0.6-22.0.0-1
Freexl Project Freexl<1.0.5
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/freexlto a version that resolves this vulnerability.Fixed in 1.0.5-3Fixed in 1.0.6-1Fixed in 1.0.6-2Fixed in 2.0.0-1
Event History
Feb 23, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What does CVE-2018-7439 refer to?
CVE-2018-7439 refers to a heap-based buffer over-read vulnerability identified in FreeXL versions prior to 1.0.5.
2
What are the affected versions of FreeXL in CVE-2018-7439?
FreeXL versions before 1.0.5 are affected by CVE-2018-7439.
3
How can I mitigate the vulnerability indicated by CVE-2018-7439?
To mitigate CVE-2018-7439, upgrade FreeXL to versions 1.0.5 or higher.
4
On which operating systems does CVE-2018-7439 affect FreeXL?
CVE-2018-7439 affects FreeXL on Debian Linux versions 7.0, 8.0, and 9.0.
5
What is the potential security risk of CVE-2018-7439?
The potential security risk of CVE-2018-7439 includes the possibility of unauthorized access or information disclosure due to the buffer over-read.