#VU86559 Heap-based buffer overflow in libxls - CVE-2023-38852
Published: February 19, 2024
libxls
libxls.sourceforge.net
Description
The vulnerability allows a remote attacker to preform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the unicode_decode_wcstombs() function in xlstool.c when parsing style records. A remote attacker can pass a specially crafted file to the application, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack.