CVE-2020-27819NULL Pointer Dereference in Project Libxls

Severity
5.5MEDIUMNVD
EPSS
0.3%
top 49.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 23
Latest updateMay 24

Description

An issue was discovered in libxls before and including 1.6.1 when reading Microsoft Excel files. A NULL pointer dereference vulnerability exists when parsing XLS cells in libxls/xls2csv.c:199. It could allow a remote attacker to cause a denial of service via crafted XLS file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5libxls_project/libxlslibxls before 1.6.2

🔴Vulnerability Details

2
GHSA
GHSA-fp3r-w9w2-jg2f: An issue was discovered in libxls before and including 12022-05-24
OSV
CVE-2020-27819: An issue was discovered in libxls before and including 12021-02-23

📋Vendor Advisories

1
Debian
CVE-2020-27819: r-cran-readxl - An issue was discovered in libxls before and including 1.6.1 when reading Micros...2020
CVE-2020-27819 — NULL Pointer Dereference | cvebase