CVE-2021-27836: Null Pointer Dereference
Published Nov 3, 2021
·Updated
An issue was discoverered in in function xlsgetWorkSheet in xls.c in libxls 1.6.2, allows attackers to cause a denial of service, via a crafted XLS file.
Affected Software
4 affected components
Libxls Project Libxls=1.6.2
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Remediation
Patch Available
Event History
Nov 3, 2021
CVE Published
via MITRE·04:07 PM
Data Sourced
via MITRE·04:07 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-27836.
2
What is the severity of CVE-2021-27836?
The severity of CVE-2021-27836 is medium with a CVSS score of 6.5.
3
How can this vulnerability be exploited?
This vulnerability can be exploited by attackers through a crafted XLS file.
4
How can I mitigate the risk associated with CVE-2021-27836?
To mitigate the risk associated with CVE-2021-27836, it is recommended to update to the latest version of libxls (1.6.3 or later) or apply the necessary patches provided by the vendor.
5
Where can I find more information about CVE-2021-27836?
You can find more information about CVE-2021-27836 on the following references: [link1], [link2], [link3].