PT-2018-15292 · Libexcel · Libexcel

Fantasyoung

·

Published

2018-12-18

·

Updated

2019-01-10

·

CVE-2018-20213

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libexcel version 0.01
Description The issue allows attackers to cause a denial of service (SEGV) via a long name in the wbook addworksheet function in workbook.c in libexcel.a.
Recommendations For libexcel version 0.01, avoid using long names in the wbook addworksheet function to prevent the denial of service.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20213

Affected Products

Libexcel