CVE-2023-38854: Buffer Overflow
Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the transcodelatin1toutf8 function in xlstool.c:296.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-38854?
CVE-2023-38854 is a buffer overflow vulnerability in libxlsv.1.6.2 that allows a remote attacker to execute arbitrary code and cause a denial of service.
How does CVE-2023-38854 affect Libxls Project Libxls?
CVE-2023-38854 affects Libxls Project Libxls version 1.6.2.
What is the severity of CVE-2023-38854?
The severity of CVE-2023-38854 is medium with a CVSS score of 6.5.
How can an attacker exploit CVE-2023-38854?
An attacker can exploit CVE-2023-38854 by crafting a malicious XLS file and sending it to the target, triggering the buffer overflow vulnerability.
Is there a fix or patch available for CVE-2023-38854?
At the time of writing, there is no available fix or patch for CVE-2023-38854. It is recommended to update to a patched version of Libxls Project Libxls when it becomes available.