CVE-2020-27819: Null Pointer Dereference
An issue was discovered in libxls before and including 1.6.1 when reading Microsoft Excel files. A NULL pointer dereference vulnerability exists when parsing XLS cells in libxls/xls2csv.c:199. It could allow a remote attacker to cause a denial of service via crafted XLS file.
Other sources
An issue was discovered in libxls reading Excel files before 1.6.1. A NULL pointer dereference vulnerability exists when parsing xls cells in libxls/xls2csv.c:199. It could allow a remote attacker to cause a denial of service via crafted xls file.
Reference: https://github.com/libxls/libxls/issues/84
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27819?
CVE-2020-27819 is a vulnerability in libxls before and including version 1.6.1 that allows a remote attacker to cause a denial of service via a crafted Microsoft Excel file.
What is the severity of CVE-2020-27819?
The severity of CVE-2020-27819 is medium, with a severity value of 5.5.
How does CVE-2020-27819 affect libxls?
CVE-2020-27819 affects libxls before and including version 1.6.1 when reading Microsoft Excel files.
How can CVE-2020-27819 be fixed?
CVE-2020-27819 can be fixed by updating libxls to version 1.6.2 or later, which resolves the vulnerability.
Is there any additional information about CVE-2020-27819?
Yes, you can find more information about CVE-2020-27819 in the references provided: [bugzilla.redhat.com](https://bugzilla.redhat.com/show_bug.cgi?id=1903296), [github.com](https://github.com/libxls/libxls/issues/84), [bugzilla.redhat.com](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1903297).