PT-2021-17634 · Readxl+2 · Readxl+2

Lockedbyte

·

Published

2021-11-03

·

Updated

2023-07-13

·

CVE-2021-27836

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: libxls version 1.6.2 readxl (affected versions not specified)
Description: An issue was discovered in the xls getWorkSheet function within xls.c in libxls, allowing attackers to cause a denial of service via a crafted XLS file. This can lead to a Denial of Service (DoS) attack when a specially crafted XLS file is utilized.
Recommendations: For libxls version 1.6.2, consider disabling the xls getWorkSheet function until a patch is available. For readxl, as the affected versions are not specified, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2021-27836
OPENSUSE-SU-2022:0142-1
OPENSUSE-SU-2024:12084-1
RSEC-2023-2

Affected Products

Debian
Libxls
Readxl