An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the parse_SST function.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade freexl | Mar 4, 2018 | Feb 23, 2018 |
| Gentoo Linux | — | Upgrade dev-libs/freexl. | Jul 28, 2020 | Feb 23, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 23, 2018 |
| Suse | — | Upgrade libfreexl1Upgrade freexl-devel | Mar 10, 2018 | Feb 23, 2018 |
| Ubuntu | — | Upgrade freexl | Nov 19, 2024 | Feb 23, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub