CVE-2017-2923
published 2018-04-24CVE-2017-2923: An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1.0.3. A specially crafted XLS file can cause…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.31%
87.3th percentile
An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| alessandro_furieri | freexl | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | freexl | < freexl 1.0.4-1 (bookworm) | freexl 1.0.4-1 (bookworm) |
| freexl_project | freexl | — | — |
| freexl_project | freexl | >= 0 < 1.0.4-1 | 1.0.4-1 |
| freexl_project | freexl | >= 0 < 1.0.4-1 | 1.0.4-1 |
| freexl_project | freexl | >= 0 < 1.0.4-1 | 1.0.4-1 |
| freexl_project | freexl | >= 0 < 1.0.4-1 | 1.0.4-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3wq9-hv2f-46q4: An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1
ghsa_unreviewed·2022-05-13
CVE-2017-2923 [HIGH] CWE-119 GHSA-3wq9-hv2f-46q4: An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1
An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
OSV
CVE-2017-2923: An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1
osv·2018-04-24·CVSS 8.8
CVE-2017-2923 [HIGH] CVE-2017-2923: An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1
An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
Debian
CVE-2017-2923: freexl - An exploitable heap based buffer overflow vulnerability exists in the 'read_biff...
vendor_debian·2017·CVSS 8.8
CVE-2017-2923 [HIGH] CVE-2017-2923: freexl - An exploitable heap based buffer overflow vulnerability exists in the 'read_biff...
An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 1.0.4-1)
bullseye: resolved (fixed in 1.0.4-1)
forky: resolved (fixed in 1.0.4-1)
sid: resolved (fixed in 1.0.4-1)
trixie: resolved (fixed in 1.0.4-1)
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: TALOS-2017-0430/0431: Multiple Vulnerabilities in FreeXL Library
blogs_talos·2017-09-11·CVSS 8.8
[HIGH] Vulnerability Spotlight: TALOS-2017-0430/0431: Multiple Vulnerabilities in FreeXL Library
## Vulnerability Spotlight: TALOS-2017-0430/0431: Multiple Vulnerabilities in FreeXL Library
Vulnerability discovered by Marcin Noga of Cisco Talos
## Overview Talos has discovered two remote code execution vulnerabilities in the the FreeXL library. FreeXL is an open source C library to extract valid data from within an Excel (.xls) spreadsheet. Exploiting these vulnerabilities can potentially allow an attacker to execute arbitrary code on the victim's machine. If an attacker builds a specially crafted XLS (Excel) file and the victim opens it with an application using the FreeXL library, the attackers code will be executed with the privileges of the local user.
## Details TALOS-2017-0430 / CVE-2017-2923 An exploitable heap based buffer overflow vulnerability exists in the read_biff_next
Talos
Vulnerability Spotlight: TALOS-2017-0430/0431: Multiple Vulnerabilities in FreeXL Library
blogs_talos·2017-09-11·CVSS 8.8
[HIGH] Vulnerability Spotlight: TALOS-2017-0430/0431: Multiple Vulnerabilities in FreeXL Library
Vulnerability discovered by Marcin Noga of Cisco Talos
### Overview Talos has discovered two remote code execution vulnerabilities in the the FreeXL library. FreeXL is an open source C library to extract valid data from within an Excel (.xls) spreadsheet. Exploiting these vulnerabilities can potentially allow an attacker to execute arbitrary code on the victim's machine. If an attacker builds a specially crafted XLS (Excel) file and the victim opens it with an application using the FreeXL library, the attackers code will be executed with the privileges of the local user.
### DetailsTALOS-2017-0430 / CVE-2017-2923An exploitable heap based buffer overflow vulnerability exists in theread_biff_next_recordfunction of the FreeXL library. The vulnerability occurs when the Binary Interchange Fil
Bugzilla
CVE-2017-2923 CVE-2017-2924 freexl: various flaws [epel-all]
bugzilla·2017-09-12·CVSS 8.8
CVE-2017-2923 [HIGH] CVE-2017-2923 CVE-2017-2924 freexl: various flaws [epel-all]
CVE-2017-2923 CVE-2017-2924 freexl: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora EPEL. Wh
Bugzilla
CVE-2017-2923 freexl: Heap-based buffer overflow in the read_biff_next_record function
bugzilla·2017-09-12·CVSS 8.8
CVE-2017-2923 [HIGH] CVE-2017-2923 freexl: Heap-based buffer overflow in the read_biff_next_record function
CVE-2017-2923 freexl: Heap-based buffer overflow in the read_biff_next_record function
An exploitable heap based buffer overflow vulnerability exists in the read_biff_next_record function of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
External References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0430
Discussion:
Created freexl tracking bugs for this issue:
Affects: epel-all [bug 1490901]
Affects: openshift-1 [bug 1490902]
http://www.securityfocus.com/bid/100807https://www.debian.org/security/2017/dsa-3976https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0430http://www.securityfocus.com/bid/100807https://www.debian.org/security/2017/dsa-3976https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0430
2018-04-24
Published