CVE-2023-38851: Buffer Overflow
Published Aug 15, 2023
·Updated
Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the xlsparseWorkBook function in xls.c:1018.
Affected Software
1 affected component
Libxls Project Libxls=1.6.2
Event History
Aug 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-38851?
CVE-2023-38851 is a buffer overflow vulnerability in libxlsv.1.6.2 that allows a remote attacker to execute arbitrary code and cause a denial of service.
2
How can a remote attacker exploit CVE-2023-38851?
A remote attacker can exploit CVE-2023-38851 by sending a crafted XLS file to the xls_parseWorkBook function in xls.c:1018.
3
What is the severity of CVE-2023-38851?
The severity of CVE-2023-38851 is medium with a CVSS score of 6.5.
4
How can I fix CVE-2023-38851?
To fix CVE-2023-38851, update libxlsv to version 1.6.3 or later.
5
Where can I find more information about CVE-2023-38851?
You can find more information about CVE-2023-38851 at the following link: [GitHub Issue](https://github.com/libxls/libxls/issues/124).