First published: Tue Dec 01 2020(Updated: )
An issue was discovered in libxls before and including 1.6.1 when reading Microsoft Excel files. A NULL pointer dereference vulnerability exists when parsing XLS cells in libxls/xls2csv.c:199. It could allow a remote attacker to cause a denial of service via crafted XLS file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libxls | <1.6.2 | 1.6.2 |
Libxls Project Libxls | <1.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27819 is a vulnerability in libxls before and including version 1.6.1 that allows a remote attacker to cause a denial of service via a crafted Microsoft Excel file.
The severity of CVE-2020-27819 is medium, with a severity value of 5.5.
CVE-2020-27819 affects libxls before and including version 1.6.1 when reading Microsoft Excel files.
CVE-2020-27819 can be fixed by updating libxls to version 1.6.2 or later, which resolves the vulnerability.
Yes, you can find more information about CVE-2020-27819 in the references provided: [bugzilla.redhat.com](https://bugzilla.redhat.com/show_bug.cgi?id=1903296), [github.com](https://github.com/libxls/libxls/issues/84), [bugzilla.redhat.com](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1903297).