CVE Database
/

CVE-2018-20452

Back to search

CVE-2018-20452

Published: Dec 25, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

The read_MSAT_body function in ole.c in libxls 1.4.0 has an invalid free that allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, because of inconsistent memory management (new versus free) in ole2_read_header in ole.c.

VendorProductVersions

n/a

n/a

affected
n/a

References

GLSA-202003-64
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now