CVE-2017-2924
published 2018-04-24CVE-2017-2924: An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1.0.3. A specially crafted XLS file can cause a…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.31%
87.3th percentile
An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| alessandro_furieri | freexl | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | freexl | < freexl 1.0.4-1 (bookworm) | freexl 1.0.4-1 (bookworm) |
| freexl_project | freexl | — | — |
| freexl_project | freexl | >= 0 < 1.0.4-1 | 1.0.4-1 |
| freexl_project | freexl | >= 0 < 1.0.4-1 | 1.0.4-1 |
| freexl_project | freexl | >= 0 < 1.0.4-1 | 1.0.4-1 |
| freexl_project | freexl | >= 0 < 1.0.4-1 | 1.0.4-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: use after free in extensions
vendor_redhat·2017-01-25·CVSS 4.3
CVE-2017-5021 [MEDIUM] chromium-browser: use after free in extensions
chromium-browser: use after free in extensions
A use after free in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Red Hat
chromium-browser: use after free in renderer
vendor_redhat·2017-01-25·CVSS 6.3
CVE-2017-5019 [MEDIUM] chromium-browser: use after free in renderer
chromium-browser: use after free in renderer
A use after free in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: address spoofing in omnibox
vendor_redhat·2017-01-25·CVSS 6.5
CVE-2017-5013 [MEDIUM] chromium-browser: address spoofing in omnibox
chromium-browser: address spoofing in omnibox
Google Chrome prior to 56.0.2924.76 for Linux incorrectly handled new tab page navigations in non-selected tabs, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Red Hat
chromium-browser: universal xss in chrome://downloads
vendor_redhat·2017-01-25·CVSS 6.1
CVE-2017-5020 [MEDIUM] chromium-browser: universal xss in chrome://downloads
chromium-browser: universal xss in chrome://downloads
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to require a user gesture for powerful download operations, which allowed a remote attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted HTML page.
Red Hat
chromium-browser: ui spoofing in blink
vendor_redhat·2017-01-25·CVSS 6.5
CVE-2017-5016 [MEDIUM] chromium-browser: ui spoofing in blink
chromium-browser: ui spoofing in blink
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elements on a page they don't control via a crafted HTML page.
Red Hat
chromium-browser: heap overflow in skia
vendor_redhat·2017-01-25·CVSS 6.3
CVE-2017-5014 [MEDIUM] chromium-browser: heap overflow in skia
chromium-browser: heap overflow in skia
Heap buffer overflow during image processing in Skia in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Red Hat
chromium-browser: universal xss in blink
vendor_redhat·2017-01-25·CVSS 6.1
CVE-2017-5006 [MEDIUM] chromium-browser: universal xss in blink
chromium-browser: universal xss in blink
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled object owner relationships, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
Red Hat
chromium-browser: universal xss in blink
vendor_redhat·2017-01-25·CVSS 6.1
CVE-2017-5008 [MEDIUM] chromium-browser: universal xss in blink
chromium-browser: universal xss in blink
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed attacker controlled JavaScript to be run during the invocation of a private script method, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
Red Hat
chromium-browser: bypass of content security policy in blink
vendor_redhat·2017-01-25·CVSS 4.3
CVE-2017-5022 [MEDIUM] chromium-browser: bypass of content security policy in blink
chromium-browser: bypass of content security policy in blink
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to properly enforce unsafe-inline content security policy, which allowed a remote attacker to bypass content security policy via a crafted HTML page.
Red Hat
chromium-browser: heap overflow in ffmpeg
vendor_redhat·2017-01-25·CVSS 5.5
CVE-2017-5024 [MEDIUM] chromium-browser: heap overflow in ffmpeg
chromium-browser: heap overflow in ffmpeg
FFmpeg in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to perform proper bounds checking, which allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
Red Hat
chromium-browser: heap overflow in v8
vendor_redhat·2017-01-25·CVSS 8.8
CVE-2017-5012 [HIGH] chromium-browser: heap overflow in v8
chromium-browser: heap overflow in v8
A heap buffer overflow in V8 in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: universal xss in blink
vendor_redhat·2017-01-25·CVSS 6.1
CVE-2017-5007 [MEDIUM] chromium-browser: universal xss in blink
chromium-browser: universal xss in blink
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled the sequence of events when closing a page, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
Red Hat
chromium-browser: ui spoofing
vendor_redhat·2017-01-25·CVSS 4.3
CVE-2017-5026 [MEDIUM] chromium-browser: ui spoofing
chromium-browser: ui spoofing
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to prevent alerts from being displayed by swapped out frames, which allowed a remote attacker to show alerts on a page they don't control via a crafted HTML page.
Red Hat
chromium-browser: heap overflow in ffmpeg
vendor_redhat·2017-01-25·CVSS 5.5
CVE-2017-5025 [MEDIUM] chromium-browser: heap overflow in ffmpeg
chromium-browser: heap overflow in ffmpeg
FFmpeg in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to perform proper bounds checking, which allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
Red Hat
chromium-browser: uninitialised memory access in webm video
vendor_redhat·2017-01-25·CVSS 4.3
CVE-2017-5017 [MEDIUM] chromium-browser: uninitialised memory access in webm video
chromium-browser: uninitialised memory access in webm video
Interactions with the OS in Google Chrome prior to 56.0.2924.76 for Mac insufficiently cleared video memory, which allowed a remote attacker to possibly extract image fragments on systems with GeForce 8600M graphics chips via a crafted HTML page.
Red Hat
chromium-browser: address spoofing in omnibox
vendor_redhat·2017-01-25·CVSS 6.5
CVE-2017-5015 [MEDIUM] chromium-browser: address spoofing in omnibox
chromium-browser: address spoofing in omnibox
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled Unicode glyphs, which allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
Red Hat
chromium-browser: out of bounds memory access in webrtc
vendor_redhat·2017-01-25·CVSS 8.8
CVE-2017-5009 [HIGH] chromium-browser: out of bounds memory access in webrtc
chromium-browser: out of bounds memory access in webrtc
WebRTC in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to perform proper bounds checking, which allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: unauthorised file access in devtools
vendor_redhat·2017-01-25·CVSS 6.5
CVE-2017-5011 [MEDIUM] chromium-browser: unauthorised file access in devtools
chromium-browser: unauthorised file access in devtools
Google Chrome prior to 56.0.2924.76 for Windows insufficiently sanitized DevTools URLs, which allowed a remote attacker who convinced a user to install a malicious extension to read filesystem contents via a crafted HTML page.
Red Hat
chromium-browser: universal xss in blink
vendor_redhat·2017-01-25·CVSS 6.1
CVE-2017-5010 [MEDIUM] chromium-browser: universal xss in blink
chromium-browser: universal xss in blink
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, resolved promises in an inappropriate context, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
Red Hat
chromium-browser: type confusion in metrics
vendor_redhat·2017-01-25·CVSS 4.3
CVE-2017-5023 [MEDIUM] chromium-browser: type confusion in metrics
chromium-browser: type confusion in metrics
Type confusion in Histogram in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to potentially exploit a near null dereference via a crafted HTML page.
Red Hat
chromium-browser: universal xss in chrome://apps
vendor_redhat·2017-01-25·CVSS 6.1
CVE-2017-5018 [MEDIUM] chromium-browser: universal xss in chrome://apps
chromium-browser: universal xss in chrome://apps
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, had an insufficiently strict content security policy on the Chrome app launcher page, which allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page.
Debian
CVE-2017-2924: freexl - An exploitable heap-based buffer overflow vulnerability exists in the read_legac...
vendor_debian·2017·CVSS 8.8
CVE-2017-2924 [HIGH] CVE-2017-2924: freexl - An exploitable heap-based buffer overflow vulnerability exists in the read_legac...
An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 1.0.4-1)
bullseye: resolved (fixed in 1.0.4-1)
forky: resolved (fixed in 1.0.4-1)
sid: resolved (fixed in 1.0.4-1)
trixie: resolved (fixed in 1.0.4-1)
GHSA
GHSA-g4rq-62r2-mf23: An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1
ghsa_unreviewed·2022-05-13
CVE-2017-2924 [HIGH] CWE-119 GHSA-g4rq-62r2-mf23: An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1
An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
OSV
CVE-2017-2924: An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1
osv·2018-04-24·CVSS 8.8
CVE-2017-2924 [HIGH] CVE-2017-2924: An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1
An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: TALOS-2017-0430/0431: Multiple Vulnerabilities in FreeXL Library
blogs_talos·2017-09-11·CVSS 8.8
[HIGH] Vulnerability Spotlight: TALOS-2017-0430/0431: Multiple Vulnerabilities in FreeXL Library
## Vulnerability Spotlight: TALOS-2017-0430/0431: Multiple Vulnerabilities in FreeXL Library
Vulnerability discovered by Marcin Noga of Cisco Talos
## Overview Talos has discovered two remote code execution vulnerabilities in the the FreeXL library. FreeXL is an open source C library to extract valid data from within an Excel (.xls) spreadsheet. Exploiting these vulnerabilities can potentially allow an attacker to execute arbitrary code on the victim's machine. If an attacker builds a specially crafted XLS (Excel) file and the victim opens it with an application using the FreeXL library, the attackers code will be executed with the privileges of the local user.
## Details TALOS-2017-0430 / CVE-2017-2923 An exploitable heap based buffer overflow vulnerability exists in the read_biff_next
Talos
Vulnerability Spotlight: TALOS-2017-0430/0431: Multiple Vulnerabilities in FreeXL Library
blogs_talos·2017-09-11·CVSS 8.8
[HIGH] Vulnerability Spotlight: TALOS-2017-0430/0431: Multiple Vulnerabilities in FreeXL Library
Vulnerability discovered by Marcin Noga of Cisco Talos
### Overview Talos has discovered two remote code execution vulnerabilities in the the FreeXL library. FreeXL is an open source C library to extract valid data from within an Excel (.xls) spreadsheet. Exploiting these vulnerabilities can potentially allow an attacker to execute arbitrary code on the victim's machine. If an attacker builds a specially crafted XLS (Excel) file and the victim opens it with an application using the FreeXL library, the attackers code will be executed with the privileges of the local user.
### DetailsTALOS-2017-0430 / CVE-2017-2923An exploitable heap based buffer overflow vulnerability exists in theread_biff_next_recordfunction of the FreeXL library. The vulnerability occurs when the Binary Interchange Fil
Bugzilla
CVE-2017-2924 freexl: Heap-based buffer overflow in the read_legacy_biff function
bugzilla·2017-09-12·CVSS 8.8
CVE-2017-2924 [HIGH] CVE-2017-2924 freexl: Heap-based buffer overflow in the read_legacy_biff function
CVE-2017-2924 freexl: Heap-based buffer overflow in the read_legacy_biff function
An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
External References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0431
Discussion:
Created freexl tracking bugs for this issue:
Affects: epel-all [bug 1490901]
Affects: openshift-1 [bug 1490902]
Bugzilla
CVE-2017-2923 CVE-2017-2924 freexl: various flaws [epel-all]
bugzilla·2017-09-12·CVSS 8.8
CVE-2017-2923 [HIGH] CVE-2017-2923 CVE-2017-2924 freexl: various flaws [epel-all]
CVE-2017-2923 CVE-2017-2924 freexl: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora EPEL. Wh
http://www.securityfocus.com/bid/100799https://www.debian.org/security/2017/dsa-3976https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0431http://www.securityfocus.com/bid/100799https://www.debian.org/security/2017/dsa-3976https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0431
2018-04-24
Published