CVE-2023-38856: Buffer Overflow
Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the getstring function in xlstool.c:411.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-38856.
What is the severity rating of CVE-2023-38856?
The severity rating of CVE-2023-38856 is medium (6.5).
How can a remote attacker exploit CVE-2023-38856?
A remote attacker can exploit CVE-2023-38856 by sending a crafted XLS file to the get_string function in xlstool.c:411, which can lead to the execution of arbitrary code and a denial of service.
Is there a fix available for CVE-2023-38856?
Yes, a fix is available for CVE-2023-38856. It is recommended to update to the latest version of libxlsv (1.6.2) to address the vulnerability.
Where can I find more information about CVE-2023-38856?
You can find more information about CVE-2023-38856 at the following reference link: [https://github.com/libxls/libxls/issues/124](https://github.com/libxls/libxls/issues/124)