Double-free error in libxls - CVE-2018-20450
Published: December 25, 2018 / Updated: December 25, 2018
libxls
libxls.sourceforge.net
Description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to insufficient validation of user-supplied input in the read_MSAT function in ole.c. A remote attacker can submit a specially crafted Excel file, trigger double-free error and cause the service to crash.