SB2017090116 - Fedora EPEL 7 update for freexl
Published: September 1, 2017 Updated: April 24, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2015-2753)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) or possibly execute arbitrary code via a crafted sector in a workbook.
2) Input validation error (CVE-ID: CVE-2015-2754)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) and possibly execute arbitrary code via a crafted workbook, related to a "premature EOF."
3) Input validation error (CVE-ID: CVE-2015-2776)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The parse_SST function in FreeXL before 1.0.0i allows remote attackers to cause a denial of service (memory consumption) via a crafted shared strings table in a workbook.
Remediation
Install update from vendor's website.