CVE-2023-38851

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Aug 15, 2023
Updated: Aug 19, 2023
CWE ID 787

Summary

CVE-2023-38851 is a buffer overflow vulnerability affecting libxlsv version 1.6.2. A maliciously crafted XLS file can be used by a remote attacker to exploit this flaw and execute arbitrary code. Additionally, the vulnerability can lead to a denial of service. The issue is located in the xls_parseWorkBook function in xls.c at line 1018. This vulnerability poses a serious risk to systems utilizing libxlsv and requires immediate attention from administrators to apply the necessary patches or updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share