CVE-2023-38852
Dashboard / Vulnerabilities / CVE-2023-38852
CVE-2023-38852
Summary:
Details: Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the unicode_decode_wcstombs function in xlstool.c:266.
References: https://lists.fedoraproject.org/archives/list/[email protected]/message/JQYGEBDBCOWBRHOW44BSSRADUOZBXHUE/, https://lists.fedoraproject.org/archives/list/[email protected]/message/YHBUPYF2NX34HNAWZ3WYHKWU3KWVQUSV/, https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38852.json, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JQYGEBDBCOWBRHOW44BSSRADUOZBXHUE/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YHBUPYF2NX34HNAWZ3WYHKWU3KWVQUSV/, https://nvd.nist.gov/vuln/detail/CVE-2023-38852, https://github.com/libxls/libxls/issues/124
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
